Legal

Data processing agreement

Last updated: 13 July 2026

This data processing agreement is drawn up in accordance with article 28 GDPR and applies when the customer has personal data processed through DuzMarc, for instance data appearing in DMARC or TLS RPT reports. By agreeing to the terms and conditions when creating an account, the customer automatically agrees to this data processing agreement as well. A separately signed copy is available on request through info@duzmarc.nl.

1. Parties

This agreement is concluded between the customer, hereinafter the controller, and Düzgün IT Services (Chamber of Commerce 99850850, VAT NL005414304B63, established in Utrecht), hereinafter the processor, as the provider of DuzMarc.

2. Subject matter and duration

The processor processes personal data solely for the purpose of supplying DuzMarc to the controller, for the duration of the underlying agreement (the subscription). Once the subscription ends, the retention and deletion periods described in article 8 apply.

3. Nature and purpose of the processing

The processor collects, decodes and structures the DMARC, TLS RPT and forensic reports that mailbox providers send about email traffic using the controller's domain, and displays them in a dashboard. These reports generally contain technical and infrastructural data (such as sending IP addresses), and occasionally personal data of data subjects at the controller or third parties, for instance when an IP address can be traced to a natural person. The categories of data subjects are: employees and users of the controller, and senders of email using the controller's domain.

4. Obligations of the processor

The processor processes personal data solely on the basis of this agreement and the documented instructions of the controller, unless a legal obligation requires otherwise. The processor imposes a duty of confidentiality on everyone with access to the data and provides appropriate technical and organisational security measures, including two-step verification for accounts, encrypted backups within the EU, and access to production systems limited to its own team.

5. Subprocessors

The controller gives general authorisation for engaging the following subprocessors. The processor informs the controller in advance of changes to this list, so that objection is possible.

PartyRoleLocation
Etheron VPS / server infrastructure The Netherlands (EU)
Soverin Domain registration and mail server for incoming reports The Netherlands (EU)
Mollie Payment processing The Netherlands (EU)
Lettermint Sending system email The Netherlands (EU)
Actalis Issuing the SSL/TLS certificate Italy (EU)
Statichost.eu Hosting of the marketing website EU
DNS4EU DNS name resolution EU
Quad9 DNS name resolution (backup, records no IP addresses) Switzerland, adequacy country

6. Transfers outside the EU

All subprocessors named in article 5 are established within the EU, with the exception of Quad9, established in Switzerland. Under the GDPR, Switzerland counts as an adequacy country; Quad9 also records no user IP addresses. Apart from this exception, no personal data is transferred to countries outside the EU.

7. Notification of data breaches

The processor notifies the controller of a security incident that may affect personal data without undue delay, and in any event within 48 hours of the processor becoming aware of it. The controller remains responsible for deciding whether to report the incident to the Dutch Data Protection Authority and to the data subjects.

8. Return and deletion

The controller can export their own report data at any time during the subscription through the settings page. Once the subscription ends, all data, backups included, is permanently deleted within a set period, unless a statutory retention obligation requires otherwise.

9. Assistance with data subject rights

The processor gives the controller reasonable assistance with requests from data subjects exercising their rights under the GDPR, insofar as those requests concern data processed through DuzMarc.

10. Audits

The controller has the right, after prior written notice and once a year, to request reasonable information about the processor's compliance with this agreement. A physical audit only takes place after mutual consultation about its form, timing and cost.

11. Liability

The processor's liability under this data processing agreement is limited as set out in article 9 of the terms and conditions.

12. Final provisions

This data processing agreement forms part of the agreement between the controller and the processor and cannot be terminated separately from it. This agreement is governed by Dutch law.

13. Contact

Questions about this data processing agreement can be sent to info@duzmarc.nl.