Data Processing Agreement

Your customer data, in good hands

Whatever you put into Glowedge remains yours. Here you can read exactly how we handle it, who else has access, and what happens if you stop using the service.

  • Only processed on your instructions
  • Data breaches reported within 48 hours
  • Export for 90 days after cancellation, then deleted

Last updated: August 2026

This English translation is provided for convenience only. The Dutch version of this document is legally binding and prevails in case of any discrepancy.

This data processing agreement is part of Glowedge's general terms and conditions and applies automatically as soon as you use the Glowedge platform. A separate signature is not required. We will send a signed copy upon request.

1. Parties and roles

You (the customer) are the controller for the personal data you enter into the platform or collect via the platform. Glowedge is the processor and processes that data exclusively on your instructions.

For data about you as a customer (account details, billing, support), Glowedge itself is the controller. Glowedge's privacy policy applies to that data, not this agreement.

2. Definitions

Terms such as personal data, processing, data subject, controller, processor, sub-processor, and personal data breach have the meanings set out in the GDPR (Regulation (EU) 2016/679). "Platform" and "Account" have the meanings set out in the general terms and conditions.

3. Purpose of processing by Glowedge

Glowedge processes personal data only to provide the platform to you, as described in Annex 1. We do not process for our own purposes and do not process anything outside of your written instructions, unless a legal obligation forces us to do so. In that case, we will inform you in advance, unless the law prohibits it.

This agreement, the general terms and conditions, and the settings you choose in the platform serve as your instructions. If we find an instruction to be in conflict with the GDPR, we will let you know.

4. Your obligations

You ensure that:

  • you have a valid legal basis for every processing activity you perform via the platform;
  • you inform data subjects via your own privacy statement;
  • you do not enter any special categories of personal data (such as health, criminal, or biometric data) into the platform, unless this has been coordinated with us in writing in advance;
  • you correctly use the platform's security settings, such as two-step verification and user roles;
  • you handle requests from data subjects yourself.

5. Obligations of Glowedge

We:

  • process only according to your instructions;
  • ensure that employees and sub-processors who have access to personal data are bound by confidentiality;
  • take the security measures set out in Annex 2;
  • assist you where reasonably possible with requests from data subjects, data protection impact assessments, and prior consultation with the supervisory authority;
  • make available all information necessary to demonstrate that we comply with Article 28 of the GDPR;
  • delete or return personal data after the end of the agreement, as described in Article 10.

Assistance with data subject requests, audits, and impact assessments that goes beyond the standard functions of the platform will be charged at an hourly rate of €175 excluding VAT.

6. Sub-processors

You give us general permission to engage sub-processors. The current list is in Annex 3. We impose at least the same obligations on each sub-processor as in this agreement and remain responsible to you for their work.

If we add or replace a sub-processor, we will inform you at least 30 days in advance by email or via the platform. If you have legitimate objections, we will consult on a solution. If we cannot reach an agreement, you may terminate the agreement as of the date the change takes effect, with a pro-rata refund of prepaid amounts.

7. Transfer outside the EEA

Some sub-processors are located in the United States. Transfer only takes place on the basis of a valid transfer mechanism: the EU-U.S. Data Privacy Framework or the standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914), supplemented by additional measures where necessary. Upon request, we will provide insight into the safeguards used.

8. Security

We take the technical and organizational measures set out in Annex 2 and keep them up to date. We may adjust measures as long as the security level does not decrease.

Security is a shared responsibility. Measures on your side, such as strong passwords, two-step verification, limiting user rights, and timely removal of departed employees, fall outside our influence and outside this agreement.

9. Personal data breaches (data breaches)

If we discover a breach that affects your personal data, we will inform you without undue delay and no later than 48 hours after discovery, so that you can report it to the Dutch Data Protection Authority or the Belgian Data Protection Authority within the legal 72 hours.

Our report contains, as far as known at that time: the nature of the breach, the categories and estimated number of data subjects and data records, the likely consequences, and the measures we have taken or propose. Information that becomes available later will be sent afterwards.

You decide if and how you report to the supervisory authority and data subjects. We do not report on your behalf, unless you ask us to do so in writing.

10. Retention, return, and deletion

We keep personal data as long as your account is active. After termination, your data remains available for 90 days to be exported via the platform's export functions. After that, we delete all personal data, including copies at sub-processors, unless a legal retention obligation prohibits deletion. Backups are overwritten according to the regular rotation schedule, no later than 30 days after deletion.

11. Control and audit

Once a year, or more often after a data breach or at the request of a supervisory authority, you may have our compliance with this agreement checked. For this purpose, we initially provide documentation, such as security policies, certifications, and audit reports from sub-processors. If that is demonstrably insufficient, an independent auditor may perform a check under confidentiality, after at least 30 days' notice, during office hours and without disrupting the service to other customers. The costs of the audit are for you.

12. Liability

The limitation of liability from the general terms and conditions also applies to this agreement. Fines from supervisory authorities resulting from your own shortcomings as a controller are for your account.

13. Duration

This agreement applies as long as we process personal data for you and ends as soon as all personal data has been deleted or returned according to Article 10.

14. Other

In the event of a conflict between this agreement and the general terms and conditions, this agreement prevails with regard to the processing of personal data. This agreement is governed by Dutch law. Questions about this agreement: [email protected].


Annex 1. Description of the processing

Subject and purpose Providing the Glowedge platform: storage of contacts, messaging (email, SMS, WhatsApp, telephony), appointment scheduling, forms, websites and funnels, payments, automations, AI assistance, and reporting.

Nature of the processing Storing, structuring, sending, receiving, analyzing, automated processing via workflows and AI, backing up, and deleting.

Categories of data subjects Customers, prospects, and leads of the customer; website visitors of the customer; employees and users of the customer.

Categories of personal data Name, email address, phone number, address, company name, and job title; content of messages, conversations, and call recordings; appointment details; form entries; payment status and invoice details (no card numbers); website behavior and tracking data; tags, notes, and fields added by the customer.

Special categories of personal data Not allowed without prior written coordination.

Duration As long as the account is active, plus 90 days after termination.

Annex 2. Technical and organizational measures

  • Encryption of data in transit (TLS 1.2 or higher) and at rest.
  • Access to production systems limited to authorized employees based on roles, with two-step verification.
  • Logging of access to and changes in personal data.
  • Daily backups, encrypted and stored geographically separated.
  • Separation of customer environments at the platform level.
  • Regular security updates and vulnerability scans at the platform provider.
  • Confidentiality obligation for all employees and sub-processors.
  • Procedure for detecting, assessing, and reporting data breaches.
  • Availability of two-step verification, user roles, and IP restrictions for the customer.
  • Deletion procedure upon termination, including sub-processors.

Annex 3. Sub-processors

Sub-processor Purpose Location Transfer mechanism
Platform and infrastructure provider Hosting and operation of the platform, email, SMS, telephony United States, with data centers in the EU and US EU-U.S. Data Privacy Framework
Anthropic AI functions (text and conversation assistance) United States EU-U.S. Data Privacy Framework or standard contractual clauses
Google AI functions, email sending via linked Google accounts Ireland and United States EU-U.S. Data Privacy Framework
Stripe Payments Europe Payment processing Ireland Not applicable (EEA)
Meta Platforms Ireland Delivery of WhatsApp messages Ireland Not applicable (EEA)
Telecom providers Delivery of SMS and voice EU and United States Standard contractual clauses

We provide the name of the platform provider upon request to customers who need this for their own processing register.