Data processing agreement
When YouthCommerce works for a client, we often gain access to personal data that does not belong to us, but rather to that client’s customers, patients, or visitors.
Examples include advertising accounts, CRM systems, tracking pixels, and the Review Management System. On this page, we explain how we handle this data.
Two roles
There are two roles involved in this processing. The client is the data controller: they determine why and how their own customers’ data is processed.
YouthCommerce acts as the processor: we process that data exclusively on behalf of and at the client’s request, for example, when managing advertising accounts, implementing tracking, or using our Review Management System.
A data processing agreement for every deal
Every agreement entered into by YouthCommerce includes a data processing agreement in accordance with Article 28 of the GDPR.
This agreement is incorporated as an integral part of the agreement itself, rather than as a separate document that must be searched for separately.
In this agreement, we specify, among other things, that YouthCommerce:
- Personal data is processed solely on the basis of written instructions from the client;
- Require everyone who has access to the data on our behalf to maintain confidentiality;
- Implements appropriate technical and organizational security measures;
- Does not engage a subprocessor without informing the client, with the option to object to any changes;
- Provides assistance when the client must respond to a request from a data subject, such as a request for access or deletion;
- Provides assistance with the obligation to report data breaches and any required DPIA;
- Upon termination of the collaboration, delete or return all personal data, at the client’s discretion;
- Makes available the information necessary to demonstrate compliance, including the ability to conduct an audit.
Sub-processors
To provide our services, we use specialized subprocessors, such as advertising platforms, including Google and Meta, and analytics tools.
The specific subprocessors used depend on the services provided to each client and are specified in the data processing agreement.
In the event of a change in the subprocessors engaged, we will notify the client, who may object to such a change.
International Transfer
To the extent that data is processed outside the European Economic Area, we ensure an appropriate legal basis for the transfer, such as the EU-U.S. Data Privacy Framework or standard contractual clauses.
Special categories of personal data
As a general rule, YouthCommerce does not process special categories of personal data, such as health data. for customers for whom this issue may be specifically relevant, we explicitly and specifically address this in the data processing agreement.
Data Breaches
In the unlikely event of a data breach, we will report it to the relevant client without undue delay so that the client can promptly fulfill its own reporting obligation to the Dutch data protection authority.
Request a data processor agreement
If you are a potential client and would like to review the data processing agreement or have questions about it, please contact us at [email protected].
See also our Privacy Statement and the Terms and Conditions, sections 9, 10, 17, 22, and 23.