This data processing agreement (“DPA”) applies when we process personal data on behalf of our customers, as required by article 28 of the GDPR. It forms part of our terms of service and is accepted when you create an account. If you need a signed copy for your records, email support@helicopterview.io.
1. Parties and roles
The customer is the controller. Meskers Web (Helicopterview), KvK 55358365, is the processor. Terms such as “personal data”, “processing” and “data breach” have the meaning given in the GDPR.
2. Subject, nature and purpose
The processor processes personal data only to provide the Service: monitoring the customer’s websites, showing results in the dashboard, sending alerts, producing reports and, if used, AI summaries. Processing lasts as long as the customer has an account.
3. Categories of data and data subjects
- Data subjects: the customer’s users and team members, the customer’s clients who receive a login or report, and contact persons the customer enters.
- Data: names, email addresses, company names, login data and activity within the account, and any personal data contained in scan results of websites the customer chooses to monitor.
The Service is not designed for special categories of personal data. The customer will not enter such data.
4. Instructions
The processor processes personal data only on documented instructions of the customer, which are given by using and configuring the Service and by these terms, unless EU or Dutch law requires otherwise. The processor informs the customer if it believes an instruction violates the GDPR.
5. Confidentiality
Everyone at the processor with access to personal data is bound by a duty of confidentiality.
6. Security
The processor takes appropriate technical and organisational measures, including: encryption in transit (TLS), hashed passwords, access restricted to authorised staff, logical separation of customer data, protection against SSRF and abuse, rate limiting, regular security updates, logging, and regular backups. The processor may update these measures as long as the level of protection does not decrease.
7. Sub-processors
The customer gives general authorisation for the use of sub-processors. Current sub-processors are: the hosting provider (a dedicated server in the European Union), Mollie B.V. for payments, Google (PageSpeed Insights API, receives public website addresses only), an email delivery provider, and an AI provider when AI features are used. The processor informs the customer at least 30 days before adding or replacing a sub-processor; the customer may object on reasonable grounds and, if no solution is found, terminate the subscription. The processor imposes the same data protection obligations on sub-processors and remains responsible for them.
8. Transfers outside the EEA
Personal data is only transferred outside the European Economic Area when an adequacy decision applies or appropriate safeguards are in place, such as the Standard Contractual Clauses.
9. Assistance
The processor helps the customer, as far as reasonably possible, to respond to requests from data subjects, and with data protection impact assessments and prior consultations, taking into account the nature of the processing. Requests from data subjects that reach the processor are forwarded to the customer.
10. Data breaches
The processor notifies the customer without undue delay, and in any case within 48 hours after discovery, of a personal data breach affecting the customer’s data, with the information the customer needs to meet its own notification obligations. The processor takes reasonable measures to limit the consequences.
11. Audits
The processor makes available the information needed to demonstrate compliance with this DPA. The customer may have an audit performed by an independent expert bound to confidentiality, at its own cost, no more than once a year and with at least 30 days’ notice, unless there are concrete indications of a breach of this DPA.
12. End of processing
When the account ends, the processor deletes the customer’s personal data within 30 days, unless the customer asks for an export before that or the law requires storage. Backups are overwritten in their normal cycle.
13. Liability and precedence
The liability provisions of the terms of service apply to this DPA. If this DPA conflicts with the terms of service on the processing of personal data, this DPA prevails.