Data processing agreement
This data processing agreement (DPA) covers personal data in the workbooks customers upload to DORA Convert. It forms part of the terms and conditions and is accepted by paying for an access code.
Effective date: 29 September 2026
1. Parties and roles
- Legal name
- CDCT
- Registered address
- Keizerskroon 64, 3353 XR Papendrecht, NL
- KvK number
- 87669234
- VAT / BTW number
- NL004466212B92
- [email protected]
The customer, the business that orders an access code, is the controller. CDCT is the processor. This DPA covers workbook content only. For contact, billing, payment, support and log data CDCT is the controller; see the privacy statement.
2. Details of the processing
- Subject matter: validating the customer's DORA Register of Information workbook and building an xBRL-CSV package from it.
- Duration: for as long as the customer uses the service. Each workbook is processed only while a validation or package build runs.
- Nature and purpose: reading and checking the workbook, checking its identifiers in public registries, building the package, offering it for download and, when the customer asks, emailing it to the customer. There is no other purpose.
- Personal data: any personal data the customer includes in the workbook.
- Data subjects: the natural persons whose data the customer includes in the workbook.
3. Obligations of CDCT (Article 28(3) GDPR)
(a) Processing only on documented instructions
CDCT processes workbook content only on the customer's documented instructions: these terms, this DPA and the validations, package builds and package emails the customer starts in the service. This includes the transfers described in section 4. If EU or Dutch law requires other processing, CDCT tells the customer first, unless that law forbids it. CDCT tells the customer if it believes an instruction breaks data protection law.
(b) Confidentiality
CDCT ensures that everyone it authorises to process workbook content is bound by a duty of confidentiality.
(c) Security of processing
CDCT takes the measures Article 32 GDPR requires. Workbooks travel over HTTPS, and uploading requires a signed-in session. Each workbook is processed in a temporary folder that is deleted when the request ends. A built package can be downloaded only in the session that built it; it is deleted once downloaded and otherwise expires shortly after it is built (currently after five minutes).
(d) Sub-processors
The customer gives general authorisation for the sub-processors in section 4. CDCT gives the customer notice of any intended addition or replacement in advance and the opportunity to object. CDCT binds each sub-processor to the same data protection obligations by contract and remains liable to the customer for its sub-processors.
(e) Assistance with data subjects' requests
Workbook content is not kept after processing (see (g)), so CDCT normally holds nothing to give access to, correct or delete. Where CDCT can help the customer answer a data subject's request, it does so with appropriate technical and organisational measures. CDCT passes any request it receives directly to the customer without delay.
(f) Assistance with security, breaches and impact assessments
CDCT helps the customer meet its duties under Articles 32–36 GDPR, taking into account the nature of the processing and the information available to CDCT. CDCT notifies the customer without undue delay after becoming aware of a personal data breach involving workbook content, and gives the information the customer needs to report it.
(g) Deletion at the end of processing
CDCT deletes workbook content as part of normal processing: the uploaded workbook when the validation or build request ends, and the built package once it is downloaded or has expired. CDCT keeps no other copies, unless EU or Dutch law requires storage. The customer already holds the package, so there is nothing to return. A package the customer has emailed to itself stays in its own mailbox.
(h) Information and audits
CDCT makes available all information needed to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, by the customer or an auditor the customer appoints. Send requests to [email protected].
4. Sub-processors
- Hostinger hosts the server that processes workbooks (VPS, Germany).
- Cloudflare carries all traffic between the customer's browser and the server, including uploaded workbooks and downloaded packages (United States; EU-US Data Privacy Framework and Standard Contractual Clauses).
- Resend delivers the package by email when the customer asks for it (United States; EU-US Data Privacy Framework and Standard Contractual Clauses).
LEI codes and VAT numbers from the workbook are checked in the public registries GLEIF and VIES. These registries receive the identifier only, never the workbook. Payments are handled by Mollie and fall outside this DPA.