Data processing agreement
Data processing agreement
With every backup, DataVault365 processes personal data on behalf of the customer. This data processing agreement sets out how we do that. It forms part of every agreement for DataVault365 and applies automatically as soon as a subscription is taken out. A signed copy is available on request.
Last updated: 5 September 2026. This is a translation for convenience; in case of differences the Dutch version prevails.
1. Parties
Parties and definitions
- Controller: the customer that has taken out a DataVault365 subscription and decides which data from its Microsoft 365 environment is backed up.
- Processor: Altena Software Development & IT Management, trading as Altena Digital (Dutch Chamber of Commerce no. 98829106), as provider of DataVault365. Referred to below as “we”.
- Backup data: the copies of data from the customer’s Microsoft 365 environment that the service stores.
The terms used follow the definitions in the General Data Protection Regulation (GDPR, EU 2016/679). The terms and conditions of DataVault365 also apply to the agreement.
2. The processing
Subject, nature and purpose of the processing
- Subject: periodically creating, storing in encrypted form and, on request, restoring backups of the customer’s Microsoft 365 environment.
- Components: Exchange Online (mailboxes, calendars, contacts), OneDrive (files), SharePoint (sites and document libraries) and Power Automate (flows and their definitions), depending on the subscription and the customer’s configuration.
- Purpose: solely delivering the service to the customer. We do not process the backup data for any purpose of our own.
- Categories of data subjects: employees of the customer and the customers, suppliers and other contacts whose data is held in the customer’s Microsoft 365 environment.
- Categories of data: all data held in the protected components, such as contact details, email communication, documents and calendar information. This may include special or sensitive categories of personal data. We have no visibility of this; the customer is responsible for the content.
- Duration: the term of the agreement plus the 30-day period in section 11.
3. Instructions
Processing on the customer’s instructions
We process the backup data solely on the customer’s documented instructions. The agreement, the configuration the customer chooses in the customer portal (which users and components are protected and with which retention period) and the restore requests the customer submits count as instructions. We do not look into the content of the backup data. If we consider an instruction to infringe the GDPR, we inform the customer immediately.
4. Obligations
Our obligations as processor
- We ensure that staff with access to systems holding backup data are bound by confidentiality.
- We implement the technical and organisational measures in section 5 and keep them up to date.
- We assist the customer with requests from data subjects and with data protection impact assessments, insofar as they concern the backup data (section 9).
- We report data breaches without undue delay and no later than 48 hours after discovery (section 8).
- We cooperate with audits (section 10).
- We keep a record of the processing we carry out for customers.
- We delete the backup data after the agreement ends (section 11).
5. Security
Technical and organisational measures
- Location. Backup data and the customer portal are hosted on servers of Strato AG in Germany. Processing takes place exclusively within the European Economic Area.
- Encrypted transfer. All connections between Microsoft 365, DataVault365 and the customer portal are encrypted (TLS).
- Encryption at rest with a customer-specific key. Backup data is stored encrypted. The key is provided by the customer in its own Microsoft Azure environment and is different for every customer. Without a valid key the backup data cannot be decrypted, not even by us. If the customer revokes the key, the backup data becomes unreadable.
- Block storage. Backup data is not stored as a single file but in separate encrypted blocks. Without the associated sequence information, files cannot be reconstructed.
- Access control. Access to systems is role-based and limited to what is necessary. The customer’s administrators sign in to the customer portal with their Microsoft account, with multi-factor authentication. As a result, the sign-in policy and MFA settings of the customer’s own Microsoft 365 environment apply. Administrative access by Altena Digital is likewise protected with multi-factor authentication.
- Logging. Management and restore actions are recorded, so it can be traced afterwards who did what.
- Separation. The backup environment is separate from the customer’s primary Microsoft 365 environment.
- Maintenance. Systems are kept up to date with security updates and monitored for suspicious activity.
6. Sub-processors
Sub-processors
For the service we engage the following sub-processor:
- Strato AG
- Berlin, Germany. Hosting of the backup storage and the customer portal.
Microsoft is not a sub-processor of ours. The customer has its own agreement with Microsoft for Microsoft 365 (the source of the backups) and for Azure (management of its own encryption key).
If we intend to engage a new sub-processor, we give notice at least 30 days in advance by email or through the customer portal. Within that period the customer may object in writing on serious grounds. If the parties cannot reach agreement, the customer may terminate the agreement as of the date the change takes effect.
7. Transfers
Transfers outside the EEA
We do not transfer backup data to countries outside the European Economic Area. Should this nevertheless be necessary for a specific service, it only takes place after written agreement with the customer and under the appropriate safeguards of Article 46 GDPR.
8. Data breaches
Notification of data breaches
In the event of a (suspected) data breach affecting the backup data, we inform the customer without undue delay and no later than 48 hours after discovery. We report at least:
- the nature and scope of the breach;
- the categories of data subjects and data concerned, insofar as known;
- the likely consequences;
- the measures taken or proposed.
The customer decides on notification to the supervisory authority and to data subjects. We provide the information needed for that.
9. Data subjects
Requests from data subjects
If we receive a request from a data subject about data in the backup data, we forward it to the customer and do not handle it ourselves. We assist the customer in responding, for example by restoring precisely which data about a person is held in a backup. Deleting individual data from existing backups is only possible insofar as the service technically allows it; otherwise the data is deleted when the retention period set by the customer expires.
10. Audits
Verification and audits
On request we provide the customer with information that allows the customer to verify our compliance with this agreement. The customer may have an audit carried out at most once a year, by itself or by an independent expert bound by confidentiality, with at least 30 days’ notice. An audit takes place during office hours and does not disrupt the service to other customers. The costs of an audit are borne by the customer, unless it reveals serious shortcomings on our part.
11. Retention and deletion
Retention period and deletion
- During the agreement we retain backup data according to the retention period the customer sets in the customer portal, up to a maximum of seven years. Older restore points are deleted automatically.
- After the agreement ends, the backup data remains available for 30 days so the customer can still restore or export data. On request we delete it earlier.
- After those 30 days we permanently delete the backup data from our systems. On request we confirm the deletion in writing.
- We are under no statutory obligation to retain backup data; such obligations only apply to our own records of the customer relationship.
12. Liability
Liability
Liability under this data processing agreement is governed by section 10 of the terms and conditions of DataVault365. Each party is liable for the fines and damage resulting from its own conduct in breach of the GDPR.
13. Governing law
Governing law and signed copy
This data processing agreement is governed by Dutch law. The parties prefer to resolve disputes by mutual agreement. If they cannot, the dispute is submitted to the competent court in the district where Altena Digital is established.
Would you like a signed copy of this agreement for your own records? Email info@datavault365.com. Additional arrangements can be discussed.
