Unless otherwise agreed, the Data Processing Agreement below applies to all personal data that is processed by Kryt B.V. in order to deliver our e-learning products to our clients from 1 July 2026 onwards. Here the previous version (2022) can be found.

Throughout this DPA, we will refer to the client as “the controller”. 

Kryt B.V., with its registered office at Stationsweg 73B in Ede, number Chamber of Commerce 57748861 is hereinafter referred to as: “the Processor’.

The Data Processing Agreement below is based on the SURF Model Processing Agreement of SURF (v4.0 December 2024) published under the CC4.0 license.

ARTICLE 1. DEFINITIONS AND MISCELLANEOUS

1.1    The terms in capitalized letters in this Data Processing Agreement have the same meaning as those in Article 4 GDPR, unless defined otherwise.

1.2    The provisions of this Processing Agreement apply to all Personal Data Processing activities conducted by the Processor for the Controller in the context of the services he provides to the Controller based on the Agreement. This Personal Data and these Processing activities are listed and described in more detail in Annex A.

1.3    The appendices to this document and any later modifications or additions are part of this Data Processing Agreement. 

ARTICLE 2. PURPOSE OF THE AGREEMENT

2.1    The Processor only processes Personal Data:

  • (i) on the instructions of the Controller,
  • (ii) according to his reasonable written instructions, and
  • (iii) as far as the Processing activities are necessary to perform the Agreement and this Data Processing Agreement.

2.1.1 The Processor may also process the Personal Data for the following internal purposes:

  • (i) To improve its own services, for example by analysing error messages, user feedback, and system performance data in order to enhance stability, speed, and user-friendliness.
  • (ii) To analyse the use of its own services, such as by examining user interactions to identify usage trends and guide future product development.
    For these Processing activities, the Processor acts as the Controller within the meaning of the GDPR. The obligations set out in Articles 2.2 and 6.1 apply accordingly to these Processing activities.

2.2 The Processor shall carry out all Processing of the Personal Data in accordance with the GDPR and other applicable data protection laws and regulations, such as the Dutch GDPR Implementation Act (Uitvoeringswet AVG) and the Telecommunications Act (Telecommunicatiewet) (hereinafter: the “Applicable Legislation”).

2.3 The Processor informs the Controller immediately if:

  • (i) an instruction by the Controller is in violation of the GDPR and/or Applicable Legislation;
  • (ii) the Processor is no longer able to comply with this Data Processing Agreement;
  • (iii) the Processor has a statutory obligation to process the Personal Data unless provision of that information is prohibited by law.

ARTICLE 3. RENDERING COOPERATION

3.1    At the Controller’s request, the Processor shall cooperate immediately to comply with the Controller’s obligations in relation to the processing of Personal Data based on the GDPR and Applicable Legislation. This cooperation, defined in more detail for several topics in this Data Processing Agreement, includes the following:

  • (i) to comply with requests by Data Subjects;
  • (ii) to implement Data Protection Impact Assessments (DPIAs) and prior consultation with the Supervisory Authorities;
  • (iii) to implement Data Transfer Impact Assessments (DTIAs);
  • (iv) to comply with requests by national or international governments.

3.2 If the Processor receives a request from a national or international government related to the processing of Personal Data, then:

  • (i) the Processor shall immediately contact the Controller, and
  • (ii) the Processor shall follow the Controller’s instructions.

ARTICLE 4. SUB-PROCESSORS

4.1    The Controller grants the Processor general authorization to engage another processor as defined in Article 28(4) of the GDPR (hereinafter: “Sub-processor”). The Sub-processors engaged by the Processor are listed in Annex A. The Processor shall follow the procedure in Article 11.3 for the intended modifications by Sub-processors.

4.2    The Processor shall remain fully liable to the Controller for the Sub-processors’ compliance with obligations.

4.3    The Processor contractually imposes the obligations of this Data Processing Agreement on the Sub-processors. The Processor shall, on request, provide the Controller with a copy of those obligations set out in a contract. The Processor is permitted to omit competition-sensitive information from the copy he provides to the Controller.

ARTICLE 5. CONFIDENTIALITY

5.1    The Processor is obligated to maintain the confidentiality of the Personal Data. Individuals working for the Processor have signed a confidentiality agreement or are otherwise bound by a duty of confidentiality. The Controller may request proof of this.

5.2    Confidentiality may be breached if this is necessary for the performance of the Agreement or this Data Processing Agreement, pursuant to Applicable Law, a ruling by a Dutch court or a court in another EU member state. In the event of a court ruling from a third country, the Processor shall first consult with the Controller before providing any Personal Data.

ARTICLE 6. SECURITY

6.1    The Processor takes appropriate technical and organizational measures as defined in Article 32 of the GDPR to protect the Personal Data. The measures implemented by the Processor are included in Annex B.

6.1.1 The Processor evaluates and updates the security measures periodically to ensure these remain compliant with the latest technology and provide an appropriate protection level. The Processor guarantees that the modifications to the security measures will not result in a lower protection level than agreed at the commencement of the Data Processing Agreement or as subsequently agreed in writing. The Processor is entitled to unilaterally amend Annex B unilaterally to the most recent security standards. The Processor informs the Controller in writing about any modifications to Annex B.

6.2    The Processor documents its security policy in writing and, upon request by the Controller, provides evidence of the implemented measures. The Controller shall treat this information as confidential except where disclosure is required by a court order or at the request of a Supervisory Authority.

ARTICLE 7. PERSONAL DATA BREACH

7.1    If the Processor experiences a personal data breach (hereinafter: “Breach”) or has a reasonable suspicion thereof, the Processor shall inform the Controller Option: immediately \ within 24 hours \ within 48 hours of the Breach. The Processor shall, when providing information, at a minimum, provide the information set out in Annex C to the contact person mentioned in that annex. If it is not possible for the Processor to provide all this information immediately, the Processor shall supply this information to the Controller in stages.

7.2    The Processor shall not notify the Supervisory Authority and/or the affected Data Subjects of any Data Breaches, unless explicitly requested in writing by the Controller.

7.3    The Processor shall take measures as soon as possible to address the causes of the Breach and to mitigate or remedy any potential adverse consequences of the Breach to the greatest extent possible.

7.4    The Parties keep the contact details in Annex C up to date and shall always immediately send any updated version to the other Party.

ARTICLE 8. AUDIT

8.1    The Processor submits to the Controller all information necessary to demonstrate compliance with the obligations set out in this Data Processing Agreement. The Processor shall annually prepare an audit report demonstrating compliance with the obligations of this Data Processing Agreement and shall provide this report upon request. The report shall be prepared by an independent and qualified third party and shall include a statement confirming that the findings accurately reflect the reality. If specific circumstances, in the opinion of the Controller, warrant it, or if the Controller suspects that the Processor is failing to fulfil its obligations, the Controller may conduct or commission its own audit. The Processor shall cooperate with such an audit, amongst others by granting access to systems and documents. The costs of such an audit shall be borne by the Controller unless the audit reveals that the Processor has failed to meet its obligations under this Data Processing Agreement.

8.3    The Controller announces the audit at least fourteen (14) days in advance. The audit shall not unreasonably disrupt the Processor’s normal business activities.

8.4    The Controller handles all information from the audit in confidence and only shares it with those partners for who that knowledge is reasonably required. Neither the Controller nor the partners referred to above shall disclose or share the outcome of the audit with third parties unless compelled by law.

8.5    If the audit shows that the Processor failed to comply with the obligations of this Data Processing Agreement, the Processor shall immediately take all reasonable measures at his own cost to ensure compliance with these obligations.

ARTICLE 9. CROSS BORDER TRANSFER OF PERSONAL DATA

9.1    The Processor may only transfer Personal Data to a country outside the European Economic Area or to an international organization if: (i) the requirements of Articles 44 through 49 of the GDPR have been met, and (ii) the Controller has been informed in writing in a timely manner before the transfer begins. The transfers that occur are documented in Annex A. For any intended change to the transfers listed in Annex A, the Processor shall follow the procedure outlined in Article 11.3.

9.2    If a transfer occurs based on an adequacy decision by the European Commission, standard contractual clauses, or binding corporate rules, the Parties shall refer to the specific relevant documents in Annex A or attach them as an appendix to this Data Processing Agreement.

9.3    If there is a change or addition to the requirements regarding cross border data transfers, for example due to court rulings, new or amended adequacy decisions or standard contractual clauses issued by the European Commission, or recommendations from Supervisory Authorities, the Processor shall take measures to comply with these revised or supplemented requirements.

ARTICLE 10           INDEMNITY AND LIABILITY

10.1 The provisions on indemnity, liability and compensation in the Agreement shall apply in full to this Data Processing Agreement.

ARTICLE 11           AMENDMENT

11.1 The Parties may amend or supplement this Data Processing Agreement only by means of a written agreement signed by both Parties, except for the modifications to the annexes described in this Data Processing Agreement.

11.2 Amendments or additions to this Data Processing Agreement shall not contravene Applicable Law.

11.3 In the event of proposed changes to Sub-processors and data transfers outside the EEA, the Processor shall observe the following:

  1. The Processor shall inform the Controller in writing at the earliest opportunity about the intended modifications.
  2. The Processor shall update Annex A with the proposed changes.
  3. Upon receipt of the change request and the updated Annex A, the Controller shall have one (1) month to submit a written, substantiated objection.
  4. In the event of an objection, the Parties shall enter into consultations. The proposed changes shall not take effect until the Parties have reached an agreement.
  5. If no solution is found within two (2) months following the objection, the Controller may terminate the Agreement with one (1) months’ notice, without being obligated to compensate costs or damages.
  6. If the Controller does not object within the specified period mentioned under clause 3, the proposed changes shall be deemed accepted after the expiration of this objection period.

ARTICLE 12. EFFECTIVE DATE, DURATION AND TERMINATION

12.1 This Data Processing Agreement shall come into force upon signature by the Parties. If the Processing of Personal Data commenced prior to the signing this Data Processing Agreement, this Data Processing Agreement shall apply retroactively as of the date on which the Processing began.

12.2 This Data Processing Agreement cannot be terminated independently of the Agreement.

12.3 Within one (1) month after the termination of the Agreement, regardless of the reason for such termination, the Processor shall destroy or return all Personal Data (including any copies held by Sub-processors). If the Controller opts for the return of the data, the Processor shall transfer the data in a commonly used format to the Controller or to another party designated by the Controller. If Annex A specifies a different retention period for specific Processing activities of Personal Data, that period shall prevail over the period in mentioned this article.

12.4 The Processor’s obligations under this Data Processing Agreement shall remain in effect until such time as the Processor no longer processes any Personal Data.

12.5 The Processor shall confirm in writing to the Controller that it has complied with all obligations in Article 12.3 upon request.

ARTICLE 13. APPLICABLE LAW, DISPUTE RESOLUTION AND HIERARCHY

13.1 This Data Processing Agreement is subject to the same law as the Agreement.

13.2 Disputes arising from this Data Processing Agreement shall be submitted to the competent court as specified in the Agreement.

13.3 The original text of this Data Processing Agreement is written in Dutch. In the event of differences in interpretation, the Dutch version shall prevail.

13.4 In the event of any conflict between this Data Processing Agreement and the Agreement concerning the Processing of Personal Data, the provisions of this Data Processing Agreement shall prevail.

Thus agreed by parties if LabBuddy is used and no other Data Processing Agreement has been agreed. Date 1 July 2026.

Annex A: Specification of the Processing of Personal Data

Description of the Processing

LabBuddy is an e-learning tool that supports teachers with their laboratory teaching.

Purposes of the Processing

Improving laboratory education by providing an online environment (LabBuddy) in which students are required to design their own experiments and answer questions. This helps students learn more from the practical sessions and work more independently. The email address and name are required for authentication and the proper functioning of the application.

Categories of Data Subjects

  • Employees of organisation
  • Students of organisatoin

Categories of Personal Data

  • Name
  • E-mail
  • Student registration number

Retention period of the Personal Data.

  • Supplier applies a retention period of 3 years.

The Sub-processors engaged by the Processor are:

Sub-processor (name including domicile)

The Personal Data processed by this Sub-processor

Specification of reason for sub-processing

Country of processing and relevant transfer mechanism

Fundaments

Name, e-mail address, Student number

Data Storage

The Netherlands

 

 

Annex B: Security measures

Version No 01, Date of latest amendment: 01-01-2022

Details of the security measures taken by the Processor:

• Information Security Management System which is certified (ISO27001) and audited annually. Further security measures include:
– Secure connection via HTTPS
– Confidentiality agreements with employees and subcontractors including processor agreements
– Information security policy
– Information security rules of conduct
– Password policy
– Audits of sub-processors
– Logging and monitoring of logging
– Change management procedure
– Separation OTA
– Software development standard
– Real-time virus protection
– Policy for handling confidential information
– PEN test

Certificates held by the Processor

ISO Certification

Kryt B.V., the company responsible for LabBuddy, operates an information security management system that complies with the requirements in ISO/IEC 27001:2022 for the development, delivery and support of e-learning software, as defined by management and in accordance with our statement of applicability. We will send you this statement of applicability on request.

Reach out to us

Please fill in the form below to schedule a demo, workshop, or training. You can also use this form to ask any other question. For technical support contact support@labbuddy.net.

What's your question about?
* mandatory

Enhancing lab education with LabBuddy

Read more...

Register for a training

Please fill in the form below to register for a training. You can also use this form to ask any other question.

What's your question about?
* mandatory