Document version
Data Processing Agreement
The article 28 GDPR arrangements between TimeToBill and the Customer, for the limited situations in which we process personal data on the Customer's behalf.
This English version is a translation provided for your convenience. In case of any discrepancy between the Dutch and English text, the Dutch Verwerkersovereenkomst prevails.
This Data Processing Agreement (DPA) completes the arrangements between STB Services ("TimeToBill") and the business customer of the TimeToBill service (the Customer) for the specific cases in which TimeToBill processes personal data on behalf of the Customer within the meaning of article 28 GDPR. For all other personal data, TimeToBill is controller; that processing is covered by the Privacy Statement.
This DPA forms an inseparable part of the Terms and Conditions. In case of conflict between the two documents, this DPA prevails insofar as processing activities under the GDPR are concerned.
1. Parties
- TimeToBill: STB Services, a sole proprietorship of Sebastiaan ten Broek, Parallelweg 30, 5223 AL 's-Hertogenbosch, Chamber of Commerce (KvK) 30226252, VAT NL001685860B73 — the Processor.
- Customer: the business customer that has an agreement with TimeToBill for use of the service — the Controller.
2. Subject and scope
TimeToBill processes personal data on the Customer's behalf only in the following, limited situations:
- Support and complaint requests. Content the Customer attaches to a support or complaint request (for example screenshots, log files, email attachments).
- IP-relay proxy for WeFact API traffic. If the Customer enables the optional IP-relay proxy, TimeToBill decrypts the HTTPS request in RAM, forwards it to WeFact and re-encrypts it. Payloads are not stored; only technical metadata (licence key, request path, upstream status code) falls under the log retention in section 10.
For all other personal data TimeToBill holds (account, company, billing, invoice, licence, support and security data), TimeToBill is controller itself and this DPA does not apply.
3. Type of personal data and categories of data subjects
| Situation | Type of personal data | Categories of data subjects |
|---|---|---|
| Support and complaint requests | Only what the Customer itself submits; typically name, email address, screenshots, log lines. | Employees of the Customer, and any third parties appearing in the submitted content. |
| IP-relay proxy | In transit: WeFact API payloads, i.e. debtor data, invoice lines, amounts. Not persistently stored. | Debtors of the Customer. |
Special categories and criminal-law data. The Customer undertakes not to include special categories of personal data (art. 9 GDPR) or criminal-law data (art. 10 GDPR) in a support request, unless agreed in writing with TimeToBill in advance.
4. Instructions
TimeToBill processes the personal data referred to in section 2 only on the Customer's written instructions. The agreement, this DPA and use of the service in accordance with the documentation qualify as such instructions. One-off additional instructions are given by the Customer by email to hello@timetobill.nl.
TimeToBill will immediately inform the Customer if, in its opinion, an instruction is in breach of the GDPR or other applicable privacy law.
5. Term
This DPA applies for as long as TimeToBill may process personal data on the Customer's behalf in the context of the agreement. Sections 13 (return/destruction), 16 (liability — see art. 15 below) and 18 (governing law and forum) survive termination.
6. Obligations of TimeToBill as processor
TimeToBill:
- processes the personal data only for the purposes described in section 2 and on the Customer's instructions;
- ensures that persons with access to the personal data are bound by confidentiality or subject to an appropriate statutory duty of confidentiality;
- implements the appropriate technical and organisational security measures described in section 9;
- keeps a record of the processing categories carried out on the Customer's behalf (art. 30(2) GDPR) and makes it available on request;
- cooperates, within the limits of section 10, with requests from data subjects who contact TimeToBill directly.
7. Subprocessors
The Customer grants TimeToBill general authorisation to engage subprocessors. The current list is published at /legal/subprocessors and includes at least: Mollie (payment processing), Hetzner (VPS hosting), WeFact (invoicing), mijn.host (email and DNS) and pCloud (off-site backups).
Changes to the list of subprocessors are announced by TimeToBill at least 30 calendar days in advance on the subprocessors page and by email to the primary account address. Within those 30 days the Customer may submit a motivated objection by email. If the parties cannot reach agreement, the Customer is entitled to terminate the agreement at no cost as of the effective date of the change.
TimeToBill imposes on each subprocessor at least the same obligations as set out in this DPA, and remains liable to the Customer for their performance (art. 28(4) GDPR).
8. Transfers outside the EEA
TimeToBill processes personal data within the European Economic Area in principle. The only transfer outside the EEA is to pCloud AG (Switzerland), under the European Commission adequacy decision for Switzerland (art. 45 GDPR). If a subprocessor is ever established in a country without an adequacy decision, TimeToBill will apply the Standard Contractual Clauses (SCCs) and inform the Customer in accordance with the procedure in section 7.
9. Security
TimeToBill implements appropriate technical and organisational measures within the meaning of article 32 GDPR, including:
- encryption in transit (TLS 1.2+) on all public endpoints;
- encryption at rest for off-site backups;
- production access limited to STB Services with multi-factor authentication on all administrative accounts;
- edge protection (rate limiting, abuse detection) on all public endpoints;
- at least annual testing of the recovery procedure;
- retention controls on support, email and technical logs as described in section 10.
TimeToBill reviews these measures periodically and adjusts them based on the state of the art and the threat landscape.
10. Cooperation with data-subject rights
If a data subject approaches TimeToBill with a request that in fact falls under the Customer's responsibility, TimeToBill forwards the request and informs the Customer within 5 business days.
TimeToBill supports the Customer in fulfilling data-subject rights (art. 15–22 GDPR) to the extent reasonably necessary. TimeToBill provides 2 hours of support free of charge per calendar year. Beyond that, an hourly rate of € 150 (excl. VAT) applies, rounded up to half hours. This rate expressly does not apply to remedying errors attributable to TimeToBill itself.
Technical logs within the scope of the IP-relay proxy (licence key, request path, HTTP status, timestamp) are retained for 30 days and automatically deleted thereafter. Incoming support content falls under the retention periods in the Privacy Statement (24 months; files with legal impact 5 years).
11. Data breaches
In the event of a (suspected) personal-data breach within the scope of this DPA, TimeToBill informs the Customer within 24 hours of detection with all information the Customer needs to meet its own notification obligation under article 33 GDPR. This includes at a minimum: the nature of the incident, the categories and (estimated) numbers concerned, likely consequences, measures taken and to be taken, and contact details for follow-up.
TimeToBill logs every (suspected) data breach internally within 24 hours of detection, regardless of whether notification to the Customer is required.
12. Audit
Once per calendar year the Customer may carry out an audit, at its own cost, of compliance with this DPA, subject to the following:
- The audit is carried out by the Customer itself or by an independent, mutually agreed external auditor bound by confidentiality.
- The Customer notifies TimeToBill in writing at least 30 calendar days in advance and describes the scope of the audit.
- The audit takes place on business days between 09:00 and 17:00, in a manner that does not materially disrupt the service.
- The costs of the audit are borne by the Customer, except where the audit demonstrates material non-compliance attributable to TimeToBill — in which case TimeToBill bears the reasonable audit costs.
- The Customer treats the audit findings confidentially and uses them solely to assess compliance with this DPA.
Instead of an audit, TimeToBill may demonstrate compliance by providing on request a recent certification report (for example a Data Pro Statement or ISO 27001 Statement of Applicability), where available and reasonably applicable.
13. End of the agreement: return or destruction
On termination of the agreement, TimeToBill deletes the personal data processed on the Customer's behalf within 30 calendar days, unless the Customer requests return in a commonly used structured format in writing within that period. In that case TimeToBill delivers the data within 30 days of the request and deletes its copies within 30 days of delivery.
Exception: statutory retention obligation. Data subject to a statutory retention obligation (in particular invoice data under art. 52 of the Dutch General State Taxes Act, *Algemene wet inzake rijksbelastingen*) is kept for the statutory term and deleted thereafter.
14. Confidentiality
TimeToBill treats the personal data it processes on the Customer's behalf confidentially. This duty of confidentiality does not end on termination of the agreement.
15. Liability
The liability regime in the Terms and Conditions applies in full to this DPA, with the following additions:
- fines imposed by a supervisory authority under the GDPR are borne by the party to whom the breach is attributable;
- each party may recover its own damage as a result of unlawful processing by the other party, within the liability cap in the Terms and Conditions;
- intent and wilful recklessness are not limited by that cap.
16. Changes
Changes to this DPA follow semantic versioning:
- PATCH for editorial changes;
- MINOR for added or clarified arrangements without detriment to the Customer;
- MAJOR for material changes to rights and obligations.
Material changes are announced by TimeToBill at least 30 days in advance by email to active Customers and by publication on this page. If the Customer objects in writing within that period and the parties fail to reach agreement, the Customer may terminate the agreement at no cost as of the effective date of the change.
Older versions remain permanently retrievable at /legal/dpa/<version>.
17. Signature
This DPA is published at /legal/dpa and, together with the Terms and Conditions, forms part of the agreement as soon as the Customer accepts the Terms and Conditions. No separate signature is therefore required.
If the Customer's legal regime requires a separately signed DPA, TimeToBill will provide an identical signed PDF on request. Request it via hello@timetobill.nl.
18. Governing law and forum
This DPA is governed by Dutch law. Disputes are exclusively submitted to the Rechtbank Oost-Brabant (District Court of East Brabant), sitting in 's-Hertogenbosch, unless mandatory law provides otherwise.
Changelog
| Version | Effective from | Change |
|---|---|---|
| 1.0.0 | 2026-04-28 | First published version. |
STB Services — Parallelweg 30, 5223 AL 's-Hertogenbosch, the Netherlands — Chamber of Commerce (KvK) 30226252 — VAT NL001685860B73 — hello@timetobill.nl