Close
Menu

Data Processing Addendum

Last updated on September 15, 2026

1. Introduction

  1. This Data Processing Addendum (“DPA”) sets out how we, Soigné B.V., process personal data on your behalf when providing the Services. We act as processor and you act as controller or, where you process on behalf of another party, as processor.
  2. This DPA forms an integral part of the Agreement. Terms defined in our Terms of Service have the same meaning here. Terms such as controller, processor, processing, personal data, data subject and personal data breach have the meaning given to them in the GDPR.
  3. We interpret this DPA in light of the GDPR. Where this DPA conflicts with another part of the Agreement, this DPA prevails for the processing of personal data on your behalf.
  4. We may update this DPA in line with the changes clause in our Terms of Service. A change will not materially reduce the level of protection provided under this DPA.

2. General Obligations

  1. We each comply with our own obligations under the GDPR.
  2. We process personal data only on your documented instructions, including those set out in the Agreement and in this DPA and its annexes, unless Union or Member State law requires otherwise. You may give further instructions during the term of the Agreement, including through your use of our Services, provided they stay within the scope of the Services.
  3. Where the law requires us to process beyond your instructions, we inform you before we do so, unless that law prohibits it on important grounds of public interest.
  4. We tell you without delay if, in our opinion, an instruction infringes the GDPR or other data protection law. We may suspend the instruction until you confirm or withdraw it.
  5. You are responsible for the lawfulness of the personal data you provide to us and for the instructions you give us, including having a valid legal basis and informing data subjects.

3. Use of Sub-Processors

  1. We need your permission to use sub-processors, but you already authorize us to use our EEA-based affiliates and the sub-processors listed in Annex 2 of this DPA.
  2. We will notify you one month before adding or changing sub-processors via email or through notice to your admin account. You can object on reasonable data protection grounds during this period, and if you do, we'll try to find alternatives. If we can't resolve your objection, you can terminate the affected part of the Agreement.
  3. When we use sub-processors, we ensure they follow the same data protection rules as we do through our contracts with them, and we remain fully responsible for their compliance with these obligations.

4. International Transfers

  1. We will only transfer personal data outside the EEA based on your documented instructions or when required by Union or Member State law, and always in compliance with GDPR international transfer rules.
  2. You agree that when we use sub-processors that transfer personal data internationally, we can ensure GDPR compliance by using the EU Commission's standard contractual clauses or another valid transfer mechanism under Chapter V GDPR. Where those clauses need to be entered into by you as controller, you authorize us to enter into them with the relevant sub-processor on your behalf.

5. Security

  1. We have implemented security measures detailed in Annex 3 of this DPA to protect personal data against unauthorized access, loss, alteration and other unlawful processing.
  2. You approve these measures and agree we can update them, as long as they meet GDPR requirements, including Article 32 GDPR, and the level of protection is not materially reduced.

6. Confidentiality

  1. We limit data access strictly to staff members who need it to perform the Services. All these staff members are bound by confidentiality obligations, either through written agreements or legal requirements.
  2. We may only disclose personal data in three cases: when you explicitly authorize it, when reasonably necessary to perform the Services and follow your instructions, or when required by law. When legally possible, we'll notify you before any such disclosure.

7. Assistance

  1. If an individual (data subject) requests to exercise their privacy rights (like access, deletion, or correction) through us, we'll forward this request to you to handle. We may inform the individual about this process. When you receive such requests directly and need our help, we'll cooperate as reasonably as possible, taking into account the nature of the processing and the information available to us.
  2. We'll help you comply with your GDPR obligations for data protection impact assessments (DPIAs) and consulting with supervisory authorities. Specifically, we'll assist when processing activities might result in high risks to individuals' rights and freedoms, and when DPIA results indicate you need to consult authorities.
  3. We'll help ensure data accuracy by promptly informing you if we discover any personal data we're processing is inaccurate or outdated. We'll also assist with implementing appropriate security measures as required by GDPR Article 32.
  4. If we believe any requested assistance goes beyond reasonable industry standards or becomes overly burdensome, we may charge our reasonable costs. We'll discuss these with you in advance and always aim to find a reasonable solution that works for both parties.

8. Data Breach

  1. In case of a data breach affecting personal data we process, we'll inform you without undue delay, conduct an investigation, and provide you with detailed information as soon as possible. Where we cannot provide all information at once, we'll provide it in phases as it becomes available. We'll take reasonable steps to minimize damage and cooperate with your communication efforts about the breach.
  2. If the data breach is primarily our fault or occurs within our processing activities (and isn't caused by following your instructions), we'll bear all our costs related to handling and fixing the breach, including investigation and mitigation measures.
  3. In all other cases of data breaches (for example, when caused by your instructions or circumstances outside our control), we may charge you reasonable costs for the activities we perform to handle the breach and implement required measures.

9. Audit

  1. You can audit our compliance with this DPA once per year, or more often if you have reasonable grounds to suspect non-compliance. You can use your internal auditor or an external auditor, who must not be a competitor of ours and must sign our confidentiality agreement. Before starting an audit, you must review our existing audit reports and show legitimate reasons for needing additional auditing.
  2. Audits must be conducted during business hours with at least one month of advance notice, and you must minimize disruption to our operations. We'll provide reasonable assistance to your auditors, and you must share the preliminary audit report with us for review. We'll work together to address any findings, and all audit reports remain confidential unless both parties approve sharing them.
  3. You'll pay all audit costs, including our reasonable expenses, unless the audit reveals material non-compliance by us (excluding non-compliance caused by following your instructions). If material non-compliance is found, each party will bear its own costs for the audit.

10. Return and Deletion

  1. When the Agreement ends, you can choose whether we should delete or return all your personal data. If you request deletion, we can provide certification that we've done so. We'll keep your data until it's deleted or returned, unless Union or Member State law requires us to retain it.
  2. If you don't tell us what to do with your personal data within 30 days after the Agreement ends, we may delete all of it, including any copies.

Annex 1 - Processing Details

This annex describes the nature, purposes and categories of personal data and data subjects that may be relevant for the Services we provide to you under the Agreement. What we actually process depends on the plan you have selected, the features you use and the data you and your team enter into the Services, so not all of the below may apply to you.

Nature and Purposes of Processing

  • Managing job applications and candidate data
  • Facilitating communication between you and your candidates
  • Managing automated notifications and updates
  • Tracking application status and progress
  • Generating and managing employment contracts
  • Scheduling of shifts and registration of worked hours and attendance
  • Registration and management of leave and absence, including sickness absence
  • Payroll and salary administration, and calculation of wage-cost and employer-cost data
  • Maintaining user accounts for your team to use the Services
  • Making customer data available to third-party integrations that you install and authorize
  • Storing documents and correspondence
  • Collection, storage and processing of user support requests to resolve user issues
  • Push/device tokens (APNs/FCM), device model, OS version, app version of the users mobile device(s)

Categories of Data Subjects

  • (Hired) candidates
  • Your employees and other workers, including on-call and temporary workers
  • Your team members that have a user account for the Services

Categories of Personal Data

(Hired) candidates:

  • Identity and contact information (name, address, email, phone number, date of birth, nationality)
  • Government identifiers (copy of national ID/passport, BSN number)
  • Professional information (CV/resume, work history, qualifications, job search details, references)
  • Recruitment data (applications, interview notes, assessments)
  • Employment and contract details (employment contract, salary, IBAN, working location, hours)

Your employees and other workers:

  • Identity and contact information (name, employee identifier, contact details)
  • Government identifiers (copy of national ID/passport, BSN number)
  • Employment and contract data (function, contract type, working hours, location, salary and wage components)
  • Attendance and scheduling data (rostered and worked shifts, hours, clock-in and clock-out)
  • Absence data, including sickness absence — data concerning health and a special category of personal data under Article 9 GDPR
  • Wage-cost and employer-cost data linked to identifiable workers

Your team members with a user account:

  • Account credentials (email and hashed password)
  • Contact information (name, email, phone number)
  • Device information (IP address, email, unique identifiers such as Soigné ID)

Special Categories of Personal Data

  • Data concerning health, in the form of sickness-absence (ziekteverzuim) records

Duration of Processing

  • In accordance with your retention settings within the Services, or else for the duration of the Agreement

Annex 2 - Sub-processors

We may engage the following sub-processors:

Sub-processorProcessing ActivitiesProcessing Location
Microsoft B.V. Evert van de Beekstraat 354, 1118 CZ Amsterdam The Netherlands Hosting, storage and processing customer data Cloud infrastructure and services provider supporting data processing activities on behalf of Soigné Within the EEA (The Netherlands)
MongoDB Limited Building Two, Number One Ballsbridge, Ballsbridge, Dublin 4 Ireland Database storage and cachingWithin the EEA (The Netherlands)
ActiveCampaign, LLC (Postmark) 1 North Dearborn St, 5th Floor Chicago, IL 60602 United States of America Email delivery Email delivery services for individual emails and/or automated email campaigns initiated from Soigné’s services United States
Bird B.V. Keizersgracht 268 1016 EV Amsterdam The Netherlands WhatsApp messaging WhatsApp message delivery services for individual messages initiated from Soigné’s services Within the EEA
Intercom R&D Unlimited Company 124 St Stephen's Green Dublin 2 Co. Dublin D02 N960 Ireland Chat support If users initiate a chat in the Soigné chatbot, Intercom receives basic info related to your case (e.g., name, email, phone number, company, country, Soigné ID). If a user includes other personal data in the support chat, this information would also be processed by Intercom. United States
Auth0 by Okta 100 1st Street, Suite 600 San Francisco, California 94105 United States of America Authentication services Auth0 receives and stores basic information in the course of authenticating into the service via federated single sign in (e.g, first and last name, business contact info, email). Within the EEA
Supabase, Inc. 548 Market St, San Francisco, CA 94104 United States of America Authentication services Supabase receives and stores basic information in the course of authenticating into the mobile app (e.g, first and last name, email). Within the EEA
Firebase 1600 Amphitheatre Pkwy, Mountain View, CA 94043 United States of America Push messages to the mobile appWithin the EEA

Annex 3 - List of Security Measures

We have currently implemented the following technical security measures:

Data Encryption and Protection

  • Transport Layer Security: Implementation of TLS 1.3 or higher for all data in transit, ensuring secure communication between clients and servers
  • Data-at-Rest Protection: Employment of encryption for all stored data, including databases, backups, and file storage systems
  • Secure Key Management: Utilization of dedicated key management service with secure storage of encryption keys

Access Control

  • Role-Based Access: Implementation of granular role-based access control with principle of least privilege, regularly reviewed and updated
  • Session Management: Automatic session termination after period of inactivity and secure session handling with encrypted tokens
  • Access Logging: Comprehensive logging of all access attempts, successful or failed, with detailed user and action information

System Security

  • Infrastructure Protection: Implementation of DDoS protection, Rate limiting, Input validation and Routing constraints
  • Patch Management: Automated system for deploying security updates across all infrastructure components with minimal service disruption
  • Monitoring Systems: Real-time monitoring of system health, performance metrics, and security events with automated alerting