Data processing agreement
Based on the European Commission's standard contractual clauses (GDPR art. 28).
Version 0.2Updated Adopted by axnet on
Basis: Commission Implementing Decision (EU) 2021/915, standard contractual clauses under art. 28(7) GDPR. The customer is the controller, axnet the processor. These clauses form part of the agreement (terms and conditions, clause 2.3) and apply from sign-up (clause 3.3); no separate acceptance is needed. The customer finds them in the console, under Legal & data.
Annex I combines Annexes I and II of the model; Annexes II and III here are Annexes III and IV of the model.
1. Purpose and scope
- These clauses ensure compliance with art. 28(3) and (4) GDPR.
- The parties are listed in Annex I.
- The clauses apply to the processing described in Annex I.
- Annexes I to III form part of the clauses.
- The clauses are without prejudice to the customer’s obligations under the GDPR.
- The clauses do not by themselves ensure compliance with chapter V GDPR (transfers).
2. Invariability
- The parties do not modify these clauses, except to add or update information in the annexes.
- The parties may include the clauses in a wider contract and add other clauses, provided these do not directly or indirectly contradict them or prejudice the rights of data subjects.
3. Interpretation
- Terms defined in the GDPR have the same meaning here.
- The clauses are read in the light of the GDPR.
- The clauses are not interpreted in a way that runs counter to the GDPR or prejudices the rights of data subjects.
4. Hierarchy
In case of conflict between these clauses and other arrangements between the parties, these clauses prevail.
5. Docking clause
- Another entity may accede with the agreement of all parties, by completing Annex I.
- From accession, it is a party, with the rights and obligations of its role.
- It has no rights or obligations for the period before accession.
6. Description of the processing
The processing, including its purposes, is described in Annex I.
7. Obligations of the parties
7.1 Instructions
- axnet processes only on documented instructions from the customer, unless Union or Dutch law requires processing. axnet then informs the customer beforehand, unless the law prohibits it. The agreement and what the customer does in the console and through the API count as instructions. The customer may give further instructions during the term; they are documented.
- axnet immediately informs the customer if, in its opinion, an instruction infringes the GDPR or other data protection law.
7.2 Purpose limitation
axnet processes only for the purposes in Annex I, unless the customer gives further instructions.
7.3 Duration
axnet processes only for the duration in Annex I.
7.4 Security
- axnet implements at least the measures in Annex II, including protection against a personal data breach. axnet takes into account the state of the art, the costs, the nature, scope, context and purposes of the processing, and the risks to data subjects.
- axnet grants staff access to personal data only as strictly necessary. They are bound by confidentiality.
7.5 Sensitive data
The customer decides which data it puts into the service. For special categories of data or criminal data (GDPR art. 9 and 10), axnet applies specific restrictions or additional safeguards as the parties agree in writing.
7.6 Documentation and compliance
- The parties can demonstrate compliance with these clauses.
- axnet deals promptly and adequately with the customer’s questions about the processing.
- axnet makes available to the customer all information needed to demonstrate compliance. axnet allows for and contributes to audits, at reasonable intervals or if there are indications of non-compliance.
- The customer may carry out the audit itself or appoint an independent auditor. An audit may include an inspection of axnet’s premises, with reasonable notice.
- The parties make this information, including audit results, available to the supervisory authority on request.
7.7 Sub-processors
- The customer gives general authorisation for the sub-processors in Annex III. axnet announces an intended addition or replacement at least 30 days in advance, by e-mail and in the console, so that the customer can object. axnet provides the information needed for that.
- axnet imposes on a sub-processor, by contract, in substance the same obligations as these clauses.
- On request, axnet provides a copy of such a contract. axnet may redact business secrets, including personal data.
- axnet remains fully responsible to the customer for the sub-processor, and notifies the customer if the sub-processor fails to meet its obligations.
- Where axnet can agree it, the contract with the sub-processor provides that if axnet has factually disappeared or become insolvent, the customer may terminate that contract and instruct the sub-processor to erase or return the personal data. Google offers standard terms only, without that right; when axnet’s contract with Google ends, Google deletes the data under its Cloud Data Processing Addendum (section 6.2).
7.8 International transfers
- axnet transfers personal data to a third country or international organisation only on the customer’s documented instructions, or where Union or Dutch law requires it, and in compliance with chapter V GDPR.
- If a sub-processor makes such a transfer, axnet and the sub-processor may ensure compliance with chapter V by using the European Commission’s standard contractual clauses (GDPR art. 46(2)), provided their conditions are met.
8. Assistance to the customer
- axnet promptly notifies the customer of any request from a data subject and does not answer it itself, unless the customer has authorised it to do so.
- axnet assists the customer with appropriate technical and organisational measures in responding to data subjects’ requests.
- Taking into account the nature of the processing and the information available to it, axnet also assists the customer with:
- a data protection impact assessment (GDPR art. 35);
- a prior consultation of the supervisory authority (GDPR art. 36);
- accurate and up-to-date data: axnet informs the customer without delay if it finds that data is inaccurate or outdated;
- the obligations of GDPR art. 32.
- The measures for this assistance are set out in Annex II.
9. Personal data breaches
9.1 At the customer
In case of a breach concerning data the customer processes, axnet assists the customer:
- in notifying the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) without undue delay and, where feasible, within 72 hours after the customer became aware of it;
- in obtaining the information for that notification: the nature of the breach, its likely consequences and the measures taken;
- in informing the data subjects when the breach is likely to result in a high risk to them (GDPR art. 34).
9.2 At axnet
In case of a breach concerning personal data axnet processes for the customer, axnet notifies the customer without undue delay, and no later than 48 hours after becoming aware of it, through the security contact the customer set in the console. The notification contains at least:
- the nature of the breach, including where possible the categories and approximate number of data subjects and records;
- a contact point for more information;
- its likely consequences, and the measures axnet took or proposes.
Information that is not available at once follows without undue delay.
10. Non-compliance and termination
- If axnet breaches these clauses, the customer may instruct axnet to suspend the processing until it complies again. axnet informs the customer promptly if it cannot comply.
- The customer may terminate the agreement insofar as it concerns the processing if:
- the processing has been suspended and axnet does not comply again within a reasonable time, and at the latest within one month;
- axnet is in substantial or persistent breach of these clauses or the GDPR;
- axnet fails to comply with a binding decision of a court or of the supervisory authority regarding these clauses.
- axnet may terminate the agreement insofar as it concerns the processing if the customer insists on an instruction that axnet has reported as infringing the law (clause 7.1).
- After termination, axnet erases all personal data or returns it, at the customer’s choice, and deletes existing copies, unless the law requires storage. Export and erasure follow the periods in clause 9 of the terms and conditions. After termination for non-payment there is no export period: axnet erases the data on termination, 30 days after the machines are stopped (terms, clauses 7.1 and 8.5). Backups expire after 7 days. Until erasure, axnet continues to ensure compliance with these clauses.
Annex I · Parties and processing
Controller
- Party
- The customer, with the company details in the console
- Contact
- The security contact in the console
- Activity
- Use of axnet’s service
- Signature
- Acceptance of the terms and conditions at sign-up (terms, clause 3.3): date and version
Processor
- Party
- axnet, a sole proprietorship registered with the Dutch Chamber of Commerce under number 98873423
- Contact
- privacy@axnet.nl · info@axnet.nl
- Activity
- Compute, storage, network and backups (hosting)
- Signature
- Publication of this version
Processing
- Data subjects
- Determined by the customer, such as its customers, staff and the users of its applications
- Data
- Determined by the customer: everything on its machines, volumes, snapshots, backups and images; also IP addresses in the firewall log and in metrics
- Sensitive data
- Determined by the customer (clause 7.5)
- Nature
- Storing, hosting, backing up and forwarding network traffic. axnet does not look into the data.
- Purpose
- Providing the service under the agreement
- Duration
- The term of the agreement, plus the periods for export and erasure
- Frequency
- Continuous
- Location
- EU-NL-1 · Amsterdam region, Netherlands, in the datacenter of Alsycon B.V. (CoC 74671960); backups in the same datacenter, on axnet's own infrastructure
Annex II · Measures
Access
- Sign-in
- Two-factor authentication mandatory for every account; passkeys; sessions to review and end
- Permissions
- Roles Owner, Admin, Billing, Member and Auditor; access per project or machine
- Policies
- Security policies per organization
- Log
- Activity and audit log per organization
- Staff
- Only axnet's owner has access; new staff sign a confidentiality agreement before they get access
Separation
- Customers
- Each customer its own organization; customers have no access to the underlying virtualisation
- Machines
- Compute in its own virtual machines; containers unprivileged
- Network
- Private networks per organization; no shared IPv4 address
Network
- Firewall
- The axnet firewall per machine: policies, review & apply, log
- Outbound mail (port 25) closed for new accounts
- Transport
- Console and API over HTTPS only
Data
- Backups
- Option per machine: daily, kept for 7 days, file-level restore
- Physical
- Datacenter (Annex I), access: Secured 24/7, with key cards
Annex III · Sub-processors
| Party | Purpose | Location | Role |
|---|---|---|---|
| Google Ireland Limited E-mail (Google Workspace) · Worldwide | E-mail (Google Workspace) | Worldwide | Subprocessor |
Google may also process data outside the EEA, such as in the United States. Clause 7.8 applies to that.
axnet announces changes at least 30 days in advance; the customer can object (clause 7.7).