Legal

Data Processing Agreement

Last updated: June 2026

This English translation is provided for your convenience. Only the Dutch version of this data processing agreement is legally binding. Read the Dutch version

This data processing agreement (“Data Processing Agreement”) forms part of the terms and conditions of BrewerSync and applies as soon as you process third parties' personal data through the service.

Parties

1. Afiant B.V., established at Lorentzstraat 89, 2665 JG Bleiswijk, Netherlands, registered with the Kamer van Koophandel under number 61946281, hereinafter: “Processor”; and

2. The customer, the natural or legal person that uses an account on BrewerSync and thereby processes third parties' personal data, hereinafter: “Controller”.

Hereinafter jointly: “Parties”.

Recitals

  • The Controller uses the BrewerSync service (“the Service”) and in doing so processes personal data for which it is the controller within the meaning of the GDPR.
  • The Processor processes this personal data solely on behalf of the Controller in order to provide the Service.
  • In this Data Processing Agreement the Parties record the arrangements required under Article 28 GDPR.

1. Definitions

Terms such as “personal data”, “processing”, “data subject”, “personal data breach” (data breach), “controller” and “processor” have the meaning given to them by the GDPR (Regulation (EU) 2016/679).

2. Subject matter, nature and duration of the processing

2.1 The Processor processes personal data solely in the context of providing the Service, as further described in Annex 1.

2.2 This Data Processing Agreement applies for the duration of the use of the Service and ends as soon as the underlying agreement ends, without prejudice to the provisions that by their nature continue to apply (such as confidentiality and deletion).

3. Instructions

3.1 The Processor processes the personal data solely on the basis of the Controller's written instructions. Use of the Service in accordance with the documentation constitutes such an instruction.

3.2 The Processor shall notify the Controller if, in its opinion, an instruction infringes the GDPR or other applicable legislation, unless that legislation prohibits such notification.

3.3 The Processor does not process the personal data for its own purposes and does not provide it to third parties, except as set out in this Data Processing Agreement or where a legal obligation so requires. In the latter case, the Processor informs the Controller in advance, unless the law prohibits this.

4. Confidentiality

The Processor ensures that persons who have access to the personal data are bound to confidentiality, whether under a statutory obligation or under an agreement.

5. Security

5.1 The Processor takes appropriate technical and organisational measures to secure the personal data against loss or unlawful processing, taking into account the state of the art and the nature of the data. The measures are described in Annex 3.

5.2 The Processor may update the security measures, provided that the level of protection is not reduced.

6. Sub-processors

6.1 The Controller gives the Processor general authorisation to engage sub-processors. The sub-processors currently engaged are listed in Annex 2.

6.2 The Processor imposes on each sub-processor the same obligations as those in this Data Processing Agreement and remains responsible to the Controller for compliance therewith.

6.3 In the event of an intended addition or replacement of a sub-processor, the Processor informs the Controller in advance, so that the Controller can raise reasonable objections. Where there is a well-founded objection that cannot be resolved, the Controller may terminate the use of the relevant functionality or the underlying agreement.

7. Data subjects' rights

7.1 The Processor provides the Controller, insofar as reasonably possible, with assistance in handling requests from data subjects to exercise their rights (access, rectification, erasure, restriction, portability and objection).

7.2 If the Processor receives a request directly from a data subject, it forwards this to the Controller and does not handle it itself, unless legally required to do so.

8. Assistance

The Processor provides the Controller with reasonable assistance in fulfilling its obligations under Articles 32 to 36 GDPR, including security, notification of personal data breaches and data protection impact assessments (DPIA), taking into account the nature of the processing and the information available to the Processor.

9. Data breaches

9.1 The Processor informs the Controller without undue delay, and at the latest within 48 hours, after it becomes aware of a personal data breach affecting the personal data it processes.

9.2 The notification contains at least the nature of the breach, the categories and numbers concerned, the likely consequences and the measures taken or proposed.

9.3 The assessment of whether a personal data breach must be reported to the Autoriteit Persoonsgegevens or to data subjects, and any such notification itself, is the responsibility of the Controller.

10. Transfers outside the EEA

The Processor processes personal data within the EEA, unless indicated otherwise in Annex 2. If a transfer to a country outside the EEA takes place, the Processor ensures an appropriate safeguard within the meaning of Chapter V GDPR, such as the European Commission's standard contractual clauses or certification under the EU-US Data Privacy Framework.

11. Audit and information

11.1 The Processor makes available to the Controller, upon request, the information necessary to demonstrate compliance with Article 28 GDPR.

11.2 The Controller may carry out (or have carried out) an audit at most once per year, provided it is announced at least four weeks in advance and conducted in a manner that disrupts the Processor's operations as little as possible. The reasonable costs of an audit are borne by the Controller, unless the audit reveals a material shortcoming.

12. Return and deletion

12.1 After termination of the underlying agreement, the Processor enables the Controller to export the personal data for at least 30 days.

12.2 Thereafter, the Processor deletes the personal data, or returns it, at the Controller's choice, except for data that the Processor is legally obliged to retain.

13. Liability

The liability arrangement in the terms and conditions of BrewerSync applies mutatis mutandis to liability under this Data Processing Agreement.

14. Final provisions

14.1 In the event of a conflict between this Data Processing Agreement and the terms and conditions, this Data Processing Agreement prevails insofar as it concerns the processing of personal data.

14.2 This Data Processing Agreement is governed by Dutch law. Disputes are submitted to the competent court in the district where the Processor is established.


Annex 1: Processing details

Subject matter and nature of the processing: storing, consulting, structuring, modifying and otherwise processing personal data that the Controller enters or has processed in the Service, for the purpose of brewery and/or festival management.

Purpose: providing the Service as described in the terms and conditions.

Categories of data subjects:

  • the Controller's users (employees);
  • the Controller's customers and business contacts;
  • participants and visitors of a festival.

Types of personal data:

  • contact and account details (name, email address, telephone number);
  • company and order data;
  • festival and visitor data, including visitor email addresses for a requested beer overview;
  • usage data.

In principle, no special categories of personal data are processed.


Annex 2: Sub-processors

Sub-processorPurposeProcessing location
SupabaseDatabase and storageEEA / US (with appropriate safeguards)
VercelHosting of the applicationEEA / US (with appropriate safeguards)
ResendSending and receiving emailEEA / US (with appropriate safeguards)
MoneybirdInvoicing and accountingEEA (Netherlands)
MolliePayment processingEEA (Netherlands)

Annex 3: Technical and organisational security measures

  • Access to data is restricted at database level (row-level security) and on the basis of role-based authorisation.
  • Connections take place via encryption (TLS).
  • Sensitive data, such as visitor email addresses, is stored encrypted.
  • Passwords are stored solely in encrypted (hashed) form.
  • Access by the Processor's employees is limited to what is necessary and is subject to confidentiality.
  • Periodic backups and logging of access and changes.
  • Hosting with sub-processors holding recognised security certifications.