Data Processing Agreement (DPA)
Last updated: 28-07-2026
Article 1 — Purpose and applicability
1.1 This data processing agreement ("DPA") forms an integral part of the agreement between Credimigo and its business customers ("Customer"), and applies insofar as Credimigo processes personal data on behalf of and under the instructions of the Customer in the performance of the agreement.
1.2 This DPA meets the requirements of Article 28 GDPR.
Article 2 — Roles
2.1 The Customer is the controller within the meaning of the GDPR.
2.2 Credimigo acts as processor and processes personal data solely on the basis of documented instructions from the Customer, unless Credimigo is otherwise required to do so by Union law or the law of the Member State to which Credimigo is subject; in that case, Credimigo shall inform the Customer of that legal requirement prior to processing, unless that law prohibits such information on important grounds of public interest.
Article 3 — Data processed and categories of data subjects
3.1 Depending on use of the Platform, Credimigo processes on behalf of the Customer, among other things:
- company data;
- personal data of contact persons (including name, e-mail address, phone number, job title);
- personal data of Debtors and their contact persons;
- invoice information;
- payment information;
- communication;
- audit data;
- log files.
3.2 The categories of data subjects include at least: customers and Debtors of the Customer, contact persons of the Customer, and employees of the Customer with access to the Platform.
Article 4 — Purposes of the processing
4.1 The processing takes place only insofar as necessary for:
- accounts receivable management;
- payment processing;
- workflow automation;
- AI analysis for the purposes of the services (including classification, Recovery Scores and communication);
- communication towards Debtors;
- customer support.
4.2 Credimigo does not process the personal data for its own purposes that are not necessary for the performance of the agreement with the Customer, except insofar as Credimigo has an independent legal basis for this (for example improving the Platform in anonymised or aggregated form, as described in the Privacy Statement).
Article 5 — Subprocessors
5.1 The Customer hereby grants Credimigo general authorisation to engage subprocessors, including for example:
- cloud hosting parties;
- AI providers;
- e-mail and communication providers;
- payment providers;
- monitoring services.
5.2 Credimigo imposes obligations on each subprocessor via an agreement equivalent to those set out in this DPA.
5.3 A current list of subprocessors is made available at the Customer's request. Credimigo informs the Customer in advance of intended changes to subprocessors, so that the Customer has the opportunity to object on reasonable grounds relating to data protection. If the parties do not reach agreement, the Customer is entitled to terminate the agreement insofar as it relates to the processing concerned.
5.4 Credimigo remains fully liable to the Customer for compliance with the obligations of subprocessors engaged by it.
Article 6 — Security
6.1 Credimigo takes appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- encryption of data, both at rest and in transit;
- access management based on role-based authorisation;
- logging and monitoring;
- regular backups;
- multi-factor authentication (MFA) for administrators;
- tenant isolation between customer environments.
6.2 Further details are set out on the Security page.
Article 7 — Data breach notification obligation
7.1 Credimigo reports a security incident that qualifies as a breach involving personal data (a "data breach") to the Customer without undue delay, and in any event within 48 hours after Credimigo became aware of it.
7.2 In doing so, Credimigo provides, insofar as known at that time, at least information about the nature of the data breach, the (suspected) data and data subjects involved, the measures taken and planned, and contact details for further information. Credimigo cooperates with any investigation to be carried out by the Customer (if required) and with any notifications to the Dutch Data Protection Authority and/or data subjects.
Article 8 — Assistance to the Customer
8.1 Taking into account the nature of the processing, Credimigo provides assistance to the Customer, where reasonably possible, in fulfilling its obligation to respond to requests from data subjects to exercise their rights, as well as in carrying out data protection impact assessments (DPIAs) and any prior consultation with the supervisory authority, insofar as this can reasonably be required of Credimigo.
Article 9 — Audit
9.1 Credimigo makes available to the Customer all information reasonably necessary to demonstrate compliance with the obligations of Article 28 GDPR, and enables audits, including inspections, by the Customer or an auditor authorised by the Customer, subject to reasonable prior notice (in principle at least thirty (30) days) and with due regard for the confidentiality and security interests of Credimigo and its other customers. The costs of such an audit are for the account of the Customer, unless the audit shows that Credimigo materially fails to comply with this DPA.
Article 10 — Deletion and return after termination
10.1 After termination of the agreement, personal data is, at the Customer's choice, deleted or returned, unless legal retention obligations (including fiscal retention periods) require longer retention. Deletion takes place within a reasonable period after termination, unless otherwise agreed.
Article 11 — Liability
11.1 The limitations of liability set out in the Terms and Conditions apply in full to this DPA, insofar as mandatory law (including Article 82 GDPR) does not preclude this.
