Data Processing Agreement
Version: 5 October 2026.
This DPA forms part of the Hookt business agreement. It governs personal data processed by Jero.Eu BV on behalf of the subscribing business. It does not govern Jero.Eu BV’s independent controller processing described in the Privacy Policy.
1. Parties and roles
Jero.Eu BVRodenbachlaan 82
3550 Heusden-Zolder
Belgium
Enterprise/VAT: BE 0843.889.409
The subscribing Customer is controller for the protected-communication purposes it determines, and Jero.Eu BV is processor for processing on its behalf. If the Customer itself acts as processor for another controller, it must have authority for these instructions and the appointment of Jero.Eu BV as subprocessor.
Customer-directed protection, recipient-specific credentials and durable verification and evidence remain subject to this DPA when a recipient later verifies the communication. Separate processing determined by Jero.Eu BV for platform security, service integrity, fraud prevention, independent audit or business administration is controller processing and remains subject to applicable data-protection law.
2. Subject matter, purposes and duration
The processing provides authorized protected sending, recipient-bound protection, QR and verification credentials, associated sending evidence, and later verification using the retained record. It lasts for the subscription and the applicable post-term retention periods for customer-controlled data, including seven years from sending for core verification and evidence records.
Ending a subscription does not automatically invalidate earlier protected communications. The Customer’s instructions include maintaining the associated verification and evidence for the agreed retention period, subject to lawful data-subject rights and other binding requirements.
3. Personal data and people concerned
- People: business senders and authorized users, recipients and other people whose data the Customer includes in a communication. Verification users can include private individuals.
- Data: organization and sender identifiers and, for new protected sends, the validated send-time sender address, recipient addresses and protected recipient-related identifiers or masked information, subject, sending times, QR or credential-related information and associated communication and submission evidence.
- Processing during sending: email body and supported attachment contents, names and metadata, as selected by the Customer. Their content may include additional or sensitive personal data; the Customer is responsible for its lawful inclusion.
- Customer-controlled verification and related evidence: event times, technical results and associated identifiers; feedback where processed for the Customer’s purposes. Separate controller-purpose records are outside this DPA.
Hookt processes email body and attachment contents only as necessary to protect and send the communication. They are not retained as part of the permanent verification record. Limited encrypted temporary material may be maintained where necessary for sending and recovery, separately from long-term verification evidence. The default technical lifetime is 24 hours; completion and expiry cleanup depend on the sending service running. It is not a guarantee of deletion of all copies at that exact time.
4. Documented instructions
We process Customer-controlled data only on documented instructions, including this agreement, authorized use of Hookt and lawful additional instructions agreed with the Customer. Instructions also govern transfers, unless Union or Member State law requires processing; in that case we will inform the Customer beforehand unless that law prohibits it. We will promptly inform the Customer if, in our opinion, an instruction infringes GDPR or other applicable Union or Member State data-protection law.
The Customer is responsible for its lawful basis, notices, authority to provide data and instructions. We will not use Customer-controlled communication data for our own unrelated advertising or sell it.
5. Confidentiality and access
Personnel authorized to process personal data must be bound by confidentiality or an appropriate statutory duty. Access is limited according to role and need, with appropriate authentication and review.
6. Security measures
We will implement appropriate technical and organizational measures under GDPR Article 32, taking account of the risks, nature of data, state of the art and costs. Measures include:
- Authenticated business and administrative access, role and organization scoping and least-privilege access.
- Encryption for selected sensitive communication and temporary sending data, protected key management and secure transport when configured for production.
- Hashed verification credential lookup, recipient-specific handling and controls to reduce exposure of sensitive content in logs.
- Rate and abuse controls, operational monitoring and audit records.
- Appropriate backup, recovery, incident response, access review and retention procedures, with regular assessment of effectiveness.
Security measures may evolve without materially reducing protection. Encryption does not remove every breach risk or notification duty. Production measures and their operation must be established before customer data is processed.
7. Subprocessors and provider information
The Customer gives general written authorization for subprocessors used for the processor activities covered by this DPA. Jero.Eu BV must make available their identity, service, processing location and applicable transfer safeguards before they process Customer-controlled data. Microsoft Azure is the planned cloud provider for hosting, application, database and infrastructure processing; the production locations and transfer arrangements must be supplied before processing starts.
Microsoft 365 provides business and contact email services to Jero.Eu BV. The Customer’s authorized Microsoft email and identity services also participate in sending and access. Stripe payment processing and Billit invoicing are planned controller-side service categories; they are not automatically subprocessors of protected-communication data. Provider roles must be assessed for the actual processing involved.
We will give reasonable advance notice of an intended addition or replacement, allowing the Customer to object on reasonable data-protection grounds before the change takes effect. We will seek a suitable solution and will not use the disputed provider for that Customer’s data while the objection remains unresolved. If no reasonable solution is available, the affected service may be ended with appropriate treatment of prepaid service that cannot be provided.
Each subprocessor must be bound by written obligations providing the same data-protection obligations required by this DPA for its activities. Jero.Eu BV remains responsible to the Customer for the subprocessor’s performance of those obligations.
8. Assisting with individual rights
Taking account of the processing, we will assist the Customer through appropriate technical and organizational measures, insofar as possible, with requests to exercise GDPR rights. Requests concerning Customer-controlled data will be referred to or handled with the Customer. We will not independently decide such a request except on its instructions or where legally required. Identification must be proportionate; an exact QR hash is not the sole means of locating data.
9. Compliance assistance and breaches
Taking account of the nature of processing and information available to us, we will assist the Customer with GDPR Articles 32–36, including security, breach assessment and notifications, impact assessments and prior consultation.
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting data processed on its behalf. We will provide available information about its nature, affected data and people, likely consequences, measures taken or proposed and a contact for follow-up. Information may be provided in stages without undue further delay, with reasonable cooperation on investigation and mitigation.
The controller’s supervisory-authority notification duty, including the GDPR 72-hour period where applicable, is separate from our processor duty to notify it without undue delay. The Customer determines required notifications to authorities and individuals with our assistance. Encryption does not automatically remove an individual-notification obligation.
10. Return, deletion and retention
At the end of processing, at the Customer’s choice, we will return or delete Customer-controlled personal data and delete existing copies, unless Union or Member State law requires storage. Export or return arrangements will be agreed in a usable form, with appropriate protection.
The end of the subscription does not by itself end the Customer’s agreed instruction to maintain core verification and evidence for seven years from sending. Other periods follow the retention policy: verification events 24 months from the event, normally 24 months for applicable feedback and audit/security records, normally 90 days for operational logs, and normally 24 months after subscription end for organization and subscription configuration. Exceptions apply only for the separately defined necessary purpose.
After deletion from active systems, residual backup copies must be removed through rotation within a maximum of 90 days and protected from ordinary use. Restoration must not circumvent deletion requirements. Controller-side accounting or legal records have their own lawful purposes and are not retained indefinitely under this DPA.
A lawful instruction to end retained verification processing will be considered with the Customer, taking account of applicable rights, legal obligations and the agreed service purpose. Retention is not an unlimited right to ignore a deletion instruction.
11. Information and audits
We will make available information necessary to demonstrate compliance with GDPR Article 28 and allow and contribute to audits, including inspections, by the Customer or its mandated auditor. Reasonable arrangements for notice, scope, confidentiality and protection of other customers may be agreed without preventing statutory audit rights or urgent justified checks. Relevant reports and documentation may support an assessment.
12. International transfers
Transfers of Customer-controlled data outside the EEA must follow documented instructions and GDPR Chapter V. Where required, we will establish an applicable adequacy basis or appropriate safeguards, such as approved standard contractual clauses and necessary supplementary measures, before the transfer. This DPA alone does not establish a transfer mechanism or promise EEA-only processing. Information on the applicable mechanism must be made available to the Customer.
13. Relationship to the business agreement
This DPA prevails over conflicting business provisions concerning processor obligations. The business agreement governs other contractual matters, including Belgian law, subject always to mandatory data-protection requirements. Changes must be transparent and prospective and cannot reduce mandatory GDPR obligations. Written DPA enquiries may be sent to Jero.Eu BV at the address in section 1.
Privacy PolicyTerms overviewContactAccount deletion information
