Data Processing Agreement
This Data Processing Agreement describes the arrangements between AI Business Academy as the processor and the client as the controller, insofar as AIBA processes personal data on behalf of the client in the context of an engagement, in particular for in-company programmes and the Cohort Programme. The Dutch-language version of this agreement is the binding legal text.
Last updated: 12 June 2026
This is the English version of our Data Processing Agreement, provided for the convenience of English-speaking clients. The Dutch version is the legally binding text.
01Parties and roles
Insofar as AIBA processes personal data of the client, its employees or its clients in the context of a programme or service, AIBA acts as processor within the meaning of Article 4(8) GDPR and the client acts as controller within the meaning of Article 4(7) GDPR.
02Subject matter and duration
This Data Processing Agreement forms an integral part of the underlying agreement between AIBA and the client and applies for the duration of that agreement. Obligations which by their nature are intended to continue remain in force after termination.
03Nature, purpose and categories
- Nature of the processing: storage, organisation, analysis and presentation of personal data within working sessions, for the purpose of the training programme.
- Purpose: delivery of working sessions, case analysis, preparation of the implementation plan, and review of work results.
- Categories of data subjects: employees and business contacts of the client, and (only insofar as the client enters them) clients of the client.
- Categories of personal data: identification and contact data, functional data within documents, no special categories of data as referred to in Article 9 GDPR unless expressly agreed otherwise.
04Instructions and confidentiality
AIBA processes personal data exclusively on the basis of written instructions from the client, unless a legal obligation requires otherwise. If AIBA is of the opinion that an instruction infringes the GDPR, AIBA informs the client thereof without delay.
AIBA ensures that persons processing the data have committed themselves to confidentiality or are bound by an appropriate statutory obligation of confidentiality.
05Security
AIBA takes appropriate technical and organisational measures, including:
- encryption of data at rest (AES-256-GCM) and in transit (TLS 1.3);
- role-based access control at row level via RLS policies;
- append-only audit log with cryptographic chain verification;
- logical separation of client environments;
- periodic vulnerability scans and dependency monitoring;
- daily backups, quarterly restore tests;
- zero-retention default for work material within working sessions.
06Sub-processors
AIBA may only engage sub-processors that meet the requirements of Article 28 GDPR. A current list is available on request via info@ai-businessacademy.nl.
In the event of an intended change of sub-processors, the client is informed at least thirty days in advance. The client has the right to object in writing, stating reasons, within that period. If the parties fail to reach agreement, the client is entitled to terminate the agreement free of charge with respect to the processing concerned.
07Transfers outside the EEA
Personal data is only processed outside the European Economic Area on the basis of a valid adequacy decision of the European Commission or Standard Contractual Clauses supplemented with additional safeguards, and only with the prior written consent of the client.
08Assistance with data subjects' rights
AIBA provides the client, insofar as reasonably possible and taking into account the nature of the processing, with the necessary assistance in responding to requests from data subjects exercising their rights under the GDPR.
09Data breaches
AIBA notifies the client of a personal data breach without undue delay, and in any event within twenty-four hours of discovery. AIBA provides the information the client needs to comply with its notification obligations towards the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and data subjects.
10Audit
The client is entitled to carry out an audit, or have one carried out by an independent third party, annually or as much more often as reasonably necessary in response to a concrete cause. Audits are announced at least four weeks in advance and carried out on business days, with due regard for business operations and the confidentiality of AIBA's other clients. AIBA may instead provide a valid SOC 2, ISO 27001 or comparable certification report.
11Termination and return
After termination of the agreement, AIBA deletes the personal data or returns it to the client, at the client's choice, within thirty days, subject to statutory retention obligations.
12Liability
AIBA's liability towards the client under or in connection with this Data Processing Agreement is governed by the liability provisions in the underlying agreement and the general terms and conditions, without prejudice to mandatory liability towards data subjects under Article 82 GDPR.
