SystemService
3 Data processing agreement
SystemService | KVK 42085208 | VAT NL005484187B64 Op Het Zant 9, 5768HH Meijel, Nederland info@systemservice.nl
Roles and processing scope
For repair customers’ and staff data, the ordering company is the controller and SystemService processes on its documented instructions. Processing lasts for the service and agreed data return or deletion period. Its purpose is managing company accounts, jobs, communications, deposits and collections, inventory and related plan features. Operations include storage, organisation, display, transmission, export and deletion.
Data categories include identity and contact details, staff and permission data, device descriptions and identifiers, job history, communications, attachments and cabinet events linked to individuals. Data subjects are repair customers, staff, representatives and others lawfully included in jobs. The service is not intended for systematic storage of special-category data or the entire contents of deposited devices. The repair business limits input to information needed for its work.
Duties and subprocessors
SystemService processes entrusted data only on documented instructions, including international transfers, unless legally required otherwise; it then informs the controller beforehand unless prohibited by law. Authorised persons are bound by confidentiality and appropriate risk-based measures are applied. SystemService flags instructions that infringe data protection law. Entrusted data is not used for its own advertising or training its own AI models.
The controller grants general written authorisation to engage the subprocessors included in the list provided to the controller before the contract is concluded. The list forms part of the contract and specifies the parties’ identities and contact details, services, categories of data, countries of processing and grounds for any transfers outside the EEA. SystemService keeps the list up to date and gives advance notice of the addition or replacement of a subprocessor, allowing sufficient time for a reasoned objection before that party begins processing. SystemService imposes equivalent data protection obligations and remains liable to the controller for their performance.
SystemService assists with data subject rights and duties concerning security, breaches, impact assessments and supervisory consultation, considering the processing and available information. It notifies the controller of a personal data breach without undue delay after becoming aware, providing available details of the event, effects and measures. Incomplete information does not delay the initial notification; further findings follow as available.
The security measures are set out in Part 6, which forms part of this agreement. SystemService provides the controller with additional information needed to demonstrate compliance and assess the safeguards, subject to confidentiality. SystemService enables audits, including inspections by the controller or an authorised auditor, while protecting other customers’ data. After the processing services end, the data and copies are returned or deleted, at the controller’s choice, unless retention is required by law. The Data Processing Agreement takes precedence in matters concerning the processing of personal data.
Retention and return of entrusted data
The agreed read-only and data retrieval service after the paid subscription ends continues for the period in Part 1. By accepting these terms, the controller instructs SystemService to retain entrusted data for that purpose. It may instruct earlier return or deletion through the profile or by contacting SystemService. The twelve-month period is a contractual arrangement, not a statutory retention obligation or marketing consent.
Part 1 sets out the export method, scope, preparation time and download period. An export request does not replace a deletion instruction. Individual data rights and controller instructions are assessed separately; a technical hold on whole-company deletion is not automatically a basis to retain every entrusted record. Any necessary further scope and reason for retention must be assessed individually.