DATA PROCESSING AGREEMENT
Pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR")
Between:
- The Cooperative using the OpenCoop platform (hereinafter "Controller" or "Data Controller")
- OpenCoop, a software service provider based in Belgium (hereinafter "Processor" or "Data Processor")
Hereinafter jointly referred to as the "Parties".
1. Subject Matter and Duration
1.1 This Data Processing Agreement ("DPA") governs the processing of personal data by the Processor on behalf of the Controller in connection with the use of the OpenCoop platform ("Platform").
1.2 This DPA shall remain in effect for the duration of the Controller's use of the Platform, as defined in the Terms & Conditions.
1.3 The Processor shall process personal data only for the purpose of providing the Platform services and in accordance with the Controller's documented instructions.
2. Nature and Purpose of Processing
2.1 The Processor provides a SaaS platform for cooperative shareholder management. Processing activities include:
- Storage and management of shareholder records
- Processing of share transactions (purchases, sales, transfers)
- Calculation and administration of dividends
- Generation of legal documents (share certificates, tax statements, annual overviews)
- Communication with shareholders on behalf of the Cooperative
- Payment matching via Belgian structured communication codes (OGM)
3. Types of Personal Data
3.1 The following categories of personal data are processed:
- Identity data: full name, date of birth, national ID number (rijksregisternummer)
- Contact data: email address, phone number, postal address
- Financial data: IBAN, BIC, share transaction history, dividend payment records
- Company data (for corporate shareholders): company name, registration number (KBO/BCE), VAT number, legal form
- Account data: login credentials (password stored as hash only), preferred language, role assignments
4. Categories of Data Subjects
4.1 The data subjects are:
- Shareholders (individuals, companies, and minors represented by legal guardians) of the Cooperative
- Cooperative administrators and staff who use the Platform
5. Processor Obligations
5.1 Confidentiality: The Processor shall ensure that all persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5.2 Security measures: The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit (TLS) and at rest
- Access controls and role-based authorisation
- Regular security audits and vulnerability assessments
- Secure development practices
- Automated backups with encryption
- National ID numbers are encrypted at the application level before storage
5.3 Sub-processor management: The Processor shall not engage another processor without prior general written authorisation of the Controller. The Controller hereby provides general authorisation for the sub-processors listed in Section 7 of this DPA. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object to such changes.
5.4 Assistance: The Processor shall assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to the Processor.
5.5 Data subject requests: The Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III of the GDPR.
6. Controller Obligations
6.1 The Controller shall:
- Ensure that it has a lawful basis for the processing of personal data through the Platform
- Provide documented instructions to the Processor regarding the processing of personal data
- Ensure that data subjects are informed about the processing of their personal data in accordance with Articles 13 and 14 of the GDPR
- Be responsible for the accuracy and lawfulness of the personal data provided to the Processor
7. Sub-processors
7.1 The Processor currently uses the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud hosting (dedicated servers) | Falkenstein, Germany (EU) |
| PostgreSQL (managed) | Relational database storage | Germany (EU) |
| Redis (managed) | Caching and message queue | Germany (EU) |
7.2 All sub-processors are located within the European Union. No personal data is transferred outside the EU/EEA.
7.3 The Processor shall impose the same data protection obligations as set out in this DPA on any sub-processor by way of a contract, ensuring that the processing of personal data meets the requirements of the GDPR.
8. Data Retention and Deletion
8.1 The Processor shall process personal data for the duration of the agreement. Upon termination of the Platform services:
- The Controller may request an export of all its data within 30 days of termination
- After the 30-day period, the Processor shall delete all personal data processed on behalf of the Controller, unless EU or Belgian law requires further storage
- Transaction data may be retained for up to 7 years to comply with Belgian accounting regulations
8.2 The Processor shall provide written confirmation of data deletion upon request by the Controller.
9. Data Breach Notification
9.1 The Processor shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach.
9.2 The notification shall include:
- A description of the nature of the breach, including the categories and approximate number of data subjects and records concerned
- The name and contact details of the Processor's point of contact
- A description of the likely consequences of the breach
- A description of the measures taken or proposed to address the breach
9.3 The Processor shall cooperate with the Controller and take such reasonable commercial steps as are directed by the Controller to assist in the investigation, mitigation, and remediation of each such personal data breach.
10. Audit Rights
10.1 The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR.
10.2 The Processor shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. Such audits shall be carried out with reasonable prior notice and during normal business hours.
10.3 The Controller shall bear the costs of any audit or inspection it initiates, unless the audit reveals a material breach of this DPA by the Processor.
11. International Transfers
11.1 All personal data processed under this DPA is stored and processed within the European Union, specifically in Germany.
11.2 The Processor shall not transfer personal data to a country outside the EU/EEA without the prior written consent of the Controller and without ensuring appropriate safeguards are in place in accordance with Chapter V of the GDPR.
12. Termination and Data Return/Deletion
12.1 Upon termination of the agreement between the Parties, the Processor shall, at the choice of the Controller:
- Return all personal data to the Controller in a structured, commonly used, and machine-readable format; or
- Delete all personal data and certify such deletion in writing
12.2 This obligation does not apply to the extent that the Processor is required by EU or Belgian law to retain some or all of the personal data.
12.3 The provisions of this DPA that by their nature should survive termination shall remain in effect after the termination of the agreement.
13. Governing Law
13.1 This DPA shall be governed by and construed in accordance with the laws of Belgium.
13.2 Any disputes arising out of or in connection with this DPA shall be submitted to the exclusive jurisdiction of the courts of Belgium.
14. Contact
For questions regarding this Data Processing Agreement:
- Email:
[email protected]
- Supervisory authority: Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), Drukpersstraat 35, 1000 Brussels,
[email protected]