Last updated

Data processing agreement

This is the standard data processing agreement of Quilyx B.V. It is concluded per assignment between Quilyx and the client or intermediary, is completed with the annex specifying the processing, and forms part of the assignment once signed. Article 2 sets out when it applies and how the roles are divided.

Article 1. Definitions

In this agreement, the terms from the General Data Protection Regulation (GDPR) have the meaning the regulation gives them, including personal data, processing, controller, processor, data subject and personal data breach. The Client means the party concluding this agreement with Quilyx. Quilyx means Quilyx B.V., with its registered office at Rijnzathe 12, 3454 PV Utrecht, the Netherlands, registered with the Dutch Chamber of Commerce under number 90180275. The annex means the specification of the processing that the parties complete for each assignment.

Article 2. When this agreement applies

This agreement applies only insofar as Quilyx, in carrying out an assignment, processes personal data on behalf of the Client and on the Client's instructions. For that processing the Client is the controller and Quilyx is the processor. The annex records which processing operations are involved, which types of personal data and data subjects they concern, and how long the data is kept.

Outside this agreement falls all processing for which Quilyx determines the purpose and means itself, including its own placement administration, the profiles of registered professionals and the business contact details of the Client itself. For that processing Quilyx is an independent controller and the privacy policy on this website applies.

This agreement forms part of the assignment for which it is concluded. Where this agreement conflicts with other arrangements about the processing of personal data, this agreement prevails.

Article 3. Processing on instructions

Quilyx processes the personal data solely for the purposes stated in the annex and on the documented instructions of the Client, unless a legal obligation requires other processing. In that case Quilyx informs the Client of the obligation beforehand, unless the law prohibits this. Quilyx does not use the data for its own purposes and does not disclose it to others, except as agreed in this agreement. If Quilyx considers that an instruction infringes the GDPR or other data protection rules, it informs the Client without delay.

Article 4. Confidentiality

The persons working with the personal data under the responsibility of Quilyx are bound to confidentiality. That obligation survives the end of the assignment.

Article 5. Security

Quilyx takes appropriate technical and organisational measures to protect the personal data, matched to the nature of the data and the risks of the processing. These include in any case: access to the data restricted to those who need it for the work, encrypted connections, access logging, and regular backups. Sensitive access credentials are stored encrypted or in a form from which the original cannot be derived. On request, Quilyx explains which measures apply to the specific assignment, so the Client can assess whether they are appropriate.

Article 6. Subprocessors

The Client gives Quilyx general authorisation to engage subprocessors. At the conclusion of this agreement these are Microsoft, for the business email environment and business cloud storage, and a Dutch hosting provider, for the private assignment environment. Quilyx concludes with every subprocessor an agreement that guarantees a level of protection for the personal data equivalent to the level of this agreement. With large suppliers, such as Microsoft, that is the data processing agreement the supplier itself uses as standard. Quilyx remains responsible towards the Client for the work of its subprocessors.

If Quilyx intends to add or replace a subprocessor, it gives notice beforehand, after which the Client may object within fourteen days. In the case of a justified objection the parties look for a solution together, and if none is found, the Client may terminate the affected part of the assignment.

Article 7. Transfers outside the EEA

With large suppliers, such as Microsoft, Quilyx does not itself determine in which country the service is delivered. If personal data is transferred by Quilyx or by a subprocessor to a country outside the European Economic Area, that transfer rests on the safeguards the GDPR provides for it, such as an adequacy decision or the standard contractual clauses of the European Commission. At Microsoft those safeguards are part of the data processing terms Microsoft uses as standard.

Article 8. Requests and rights of data subjects

If Quilyx receives a request from a data subject about personal data processed under this agreement, for instance for access or erasure, it forwards the request to the Client without undue delay and does not answer it itself. Quilyx assists the Client, insofar as reasonably possible, in answering such requests and in meeting the Client's other GDPR obligations, including the security of the processing, breach notification and a data protection impact assessment.

Article 9. Data breaches

If Quilyx discovers a personal data breach affecting data processed under this agreement, it notifies the Client without undue delay. The notification describes what happened, which data and data subjects are likely affected, the possible consequences, and the measures taken or proposed. The assessment of whether the breach must be reported to the Dutch Data Protection Authority or to data subjects rests with the Client. Quilyx supplies the information the Client reasonably needs for this and documents the breach.

Article 10. Audits

On request, Quilyx makes available the information necessary to demonstrate compliance with this agreement. In addition, the Client may have an audit carried out, at most once a year and after reasonable notice, by an independent expert bound to confidentiality. Each party bears its own costs of such an audit, and the audit does not disrupt the operations of Quilyx more than necessary.

Article 11. Term, termination and return

This agreement applies for as long as Quilyx processes personal data on behalf of the Client. When the assignment ends, Quilyx, at the choice of the Client, returns the personal data in a common file format or deletes it, including copies, unless a statutory retention obligation requires storage. Quilyx confirms the deletion in writing.

Article 12. Liability

Liability under this agreement is governed by the arrangements the parties have made in the assignment. In their absence, the statutory rules of the GDPR apply, including article 82 on the division of liability between controller and processor.

Article 13. Governing law

This agreement is governed by Dutch law. Disputes are submitted to the competent court in the district where Quilyx has its registered office.

Annex. Specification of the processing

The parties complete this annex for each assignment and sign it together with the agreement.

  • Assignment. The assignment or contract to which this data processing agreement relates, with its date or reference.
  • Purpose of the processing. What Quilyx processes the personal data for.
  • Nature of the processing. For instance receiving, storing, organising, consulting or forwarding.
  • Types of personal data. For instance name, business contact details or data from a CV.
  • Categories of data subjects. For instance employees or candidates of the Client.
  • Retention period. How long Quilyx keeps the data for the assignment, or the event after which it is deleted.
  • Particulars. Deviating or additional arrangements, for instance about specific security measures.

Version July 2026.