ENDOXIA B.V.
DATA PROCESSING AGREEMENT
Data Processing Agreement
Data Processing Agreement — part of every Agreement between Endoxia B.V. and the Customer.
VERSION
1.0
STATUS
Final
EFFECTIVE DATE
1 June 2026
DOCUMENT TYPE
Data Processing Agreement
Endoxia B.V.
Tweede Jan van der Heijdenstraat 16-1, 1073 VH Amsterdam, The Netherlands
endoxia.com · privacy@endoxia.com
Confidential · © 2026 Endoxia B.V. · All rights reserved.
DATA PROCESSING AGREEMENT endoxia.com
Table of Contents
1. Parties 2
2. Purpose and scope 2
3. Definitions 2
4. Subject matter of the processing 3
5. Categories of data subjects 3
6. Categories of personal data 3
7. Instructions 4
8. Confidentiality 4
9. Security 4
10. AI processing 5
11. Location of processing 5
12. Sub-processors 5
13. Requests from data subjects 6
14. DPIA and supervisory authorities 6
15. Data breaches 6
16. Audits 6
17. Retention periods 7
18. Deletion and return 7
19. Liability 7
20. Order of precedence 7
21. Governing law 7
Annex 1 — Processing Specification 8
Endoxia B.V. — Data Processing Agreement Page of
DATA PROCESSING AGREEMENT endoxia.com
This Data Processing Agreement (“DPA”) forms an integral part of every agreement between Endoxia B.V. (“Processor”) and the Customer (“Controller”).
1. Parties
CONTROLLER
The Customer using the Platform.
PROCESSOR
Endoxia B.V.
Tweede Jan van der Heijdenstraat 16-1
1073 VH Amsterdam
The Netherlands
Website: endoxia.com
Email: privacy@endoxia.com
2. Purpose and scope
2.1 This Data Processing Agreement governs any processing of Personal Data that Endoxia carries out on behalf of the Customer in the context of providing the Platform and the Services.
2.2 This Data Processing Agreement applies solely to processing where the Customer qualifies as controller and Endoxia as processor within the meaning of the GDPR.
2.3 If Endoxia processes personal data for its own purposes, the Endoxia Privacy Statement applies.
3. Definitions
For the purposes of this Data Processing Agreement, terms from the GDPR have the same meaning. These include, among others:
GDPR
Regulation (EU) 2016/679.
Personal Data
any information relating to an identified or identifiable natural person.
Data Subject
the person to whom Personal Data relates.
Processing
any operation concerning Personal Data as referred to in Article 4 of the GDPR.
Sub-processor
any third party engaged by Endoxia for the processing of Personal Data.
Personal Data Breach (Data Breach)
a breach as referred to in Article 4 of the GDPR.
4. Subject matter of the processing
4.1 Endoxia processes Personal Data solely for the purpose of executing the Agreement.
4.2 Processing may include, among other things:
storage;
hosting;
structuring;
document analysis;
search functionalities;
AI processing;
text generation;
summarisation;
classification;
indexing;
security;
logging;
backup;
support.
4.3 Endoxia processes Personal Data solely on the basis of documented instructions from the Customer, unless otherwise required by a legal obligation.
5. Categories of data subjects
Processing may relate to, among others:
clients of the Customer;
counterparties;
employees;
directors;
shareholders;
contracting parties;
suppliers;
advisers;
parties to proceedings;
End Users;
other individuals appearing in documents processed by the Customer.
6. Categories of personal data
Processing may relate to:
names;
contact details;
email addresses;
phone numbers;
addresses;
identification data;
financial data;
contract data;
correspondence;
legal documents;
client files;
metadata;
log data;
documents;
special categories of personal data;
criminal data,
to the extent such data is entered by the Customer.
7. Instructions
7.1 Endoxia processes Personal Data strictly in accordance with:
a. the Agreement;
b. this Data Processing Agreement;
c. written instructions from the Customer.
7.2 If Endoxia believes that an instruction infringes the GDPR or other privacy legislation, Endoxia will inform the Customer accordingly.
8. Confidentiality
8.1 Endoxia ensures that all persons with access to Personal Data are bound by appropriate confidentiality obligations.
8.2 These confidentiality obligations persist after termination of the activities.
9. Security
9.1 Endoxia takes appropriate technical and organisational measures as referred to in Article 32 of the GDPR.
9.2 These measures include, among other things:
access control;
role-based authorisations;
encryption in transit;
secure storage;
network security;
logging;
monitoring;
multi-factor authentication where appropriate;
backups;
recovery procedures;
patch management;
vulnerability management.
9.3 Endoxia periodically assesses these measures and adjusts them where necessary.
10. AI processing
10.1 Endoxia uses Personal Data solely for providing the agreed functionalities.
10.2 The Customer's Personal Data is not used for:
training of AI models;
fine-tuning of AI models;
improving AI models,
unless the Customer has given prior explicit consent for this.
10.3 Endoxia takes reasonable measures to ensure that Personal Data is not used for unauthorised model training by engaged suppliers.
11. Location of processing
11.1 Personal Data is stored and processed within the European Economic Area.
11.2 If transfer outside the EEA becomes necessary, Endoxia will only use a valid transfer mechanism under the GDPR.
11.3 Endoxia implements appropriate safeguards, including Standard Contractual Clauses where required.
12. Sub-processors
12.1 The Customer grants general consent for the use of Sub-processors.
12.2 Endoxia maintains an up-to-date overview of the Sub-processors used.
12.3 Endoxia announces new Sub-processors in advance.
12.4 The Customer may object, with reasons, within fourteen (14) days if a new Sub-processor presents a demonstrable privacy or security risk.
12.5 Endoxia imposes privacy obligations on every Sub-processor that are materially equivalent to this Data Processing Agreement.
12.6 Endoxia remains responsible for the performance of its Sub-processors.
13. Requests from data subjects
13.1 As far as possible, Endoxia enables the Customer to handle requests from data subjects.
13.2 This concerns, among others, requests regarding:
access;
rectification;
erasure;
data portability;
restriction;
objection.
13.3 Endoxia does not handle such requests independently, unless legally required to do so.
14. DPIA and supervisory authorities
14.1 Endoxia provides reasonable assistance with:
Data Protection Impact Assessments;
prior consultations;
investigations by supervisory authorities.
14.2 Endoxia may charge reasonable costs for this if the work exceeds normal service provision.
15. Data breaches
15.1 Endoxia informs the Customer without undue delay after becoming aware of a Data Breach.
15.2 The notification contains, as far as available:
the nature of the incident;
the categories of data concerned;
the categories of individuals concerned;
the likely consequences;
the measures taken;
a contact person.
15.3 Endoxia provides reasonable assistance in investigation and mitigation.
15.4 The Customer remains responsible for reporting to supervisory authorities and data subjects, unless otherwise required under applicable law.
16. Audits
16.1 The Customer may perform an audit once per calendar year.
16.2 Audits must:
be announced at least thirty (30) days in advance;
take place during normal office hours;
not unreasonably disrupt business operations.
16.3 Endoxia may provide recent audit reports, certifications, or security assessments instead of a physical audit.
16.4 The costs of audits are borne by the Customer.
17. Retention periods
17.1 Personal Data is not retained longer than necessary for the execution of the Agreement.
17.2 Upon termination of the Agreement, Endoxia deletes Personal Data in accordance with its deletion policy, unless:
legal retention obligations apply;
a dispute is pending;
security reasons require temporary retention.
17.3 Backups are deleted according to regular backup cycles.
18. Deletion and return
18.1 At the Customer's request, Endoxia returns the available Personal Data.
18.2 If return is not requested, Endoxia deletes the data within a reasonable period after termination of the services.
18.3 Technical backup copies may persist for the duration of the normal retention period, provided they are adequately secured.
19. Liability
19.1 The liability arrangement from the Agreement applies in full to this Data Processing Agreement.
19.2 To the extent permitted by law, Endoxia's total liability is limited to the amount paid by the Customer to Endoxia during the twelve (12) months preceding the event giving rise to damage.
19.3 Nothing in this Data Processing Agreement limits liability to the extent such limitation is not permitted under the GDPR.
20. Order of precedence
In the event of a conflict between (a) the Agreement, (b) this Data Processing Agreement, and (c) the General Terms and Conditions, the following order of precedence applies:
Data Processing Agreement;
Agreement;
General Terms and Conditions.
21. Governing law
21.1 This Data Processing Agreement is exclusively governed by Dutch law.
21.2 Disputes shall be submitted exclusively to the competent court in Amsterdam.
Annex 1 — Processing Specification
Component
Specification
Purpose of processing
The provision of an AI-driven software platform for professional document processing, knowledge extraction, analysis, workflow support, and product functionalities.
Categories of data subjects
Clients, employees, directors, shareholders, contracting parties, counterparties, suppliers, advisers, End Users, and other individuals appearing in Customer documents.
Categories of personal data
Identification data, contact details, file data, correspondence, contract data, financial data, special categories of personal data, and criminal personal data, to the extent entered by the Customer.
Processing duration
For the duration of the Agreement and the applicable deletion period.
Sub-processors
An up-to-date list is available upon request via privacy@endoxia.com.
