Data processing agreement
Version 1.0 · effective from 10 October 2026 · part of every contract with a business customer.
Parties. The customer, as controller. Den Otter Consulting, trading as Keepstone, as processor.
Article 1. Subject and term. The processor processes personal data of the customer's clients, contacts and email recipients, solely to make the second brain and, for a refresh, to update it. This agreement runs for as long as the processor keeps data of the customer.
Article 2. Data and data subjects.
| Data subjects | Data |
|---|---|
| The customer's clients | Name (only if the customer ticks this per client), role, sector, projects, amounts |
| Contacts at those clients | Name, job title, contact details in uploads |
| Recipients of uploaded emails | Name, email address, content of the email |
Special category data is not covered. The customer does not provide it (terms and conditions, article 4.5).
Article 3. Instructions. The processor only processes on the customer's instructions. That instruction is: make the second brain as described on keepstoneai.eu and in this agreement. By accepting, the customer also determines the questions, the retention period of 30 days and the list of sub-processors. If the customer wants a shorter retention period or less data, the processor follows that instruction. If, in the processor's view, an instruction infringes the GDPR, it tells the customer straight away. If EU or Member State law requires the processor to process the data, it tells the customer before processing, unless that law prohibits this.
Article 4. Confidentiality. The processor keeps the data confidential. The processor works alone and gives nobody else access, except the sub-processors on the list of sub-processors.
Article 5. Security. The processor takes appropriate technical and organisational measures to protect the data, at least these. Names the customer provides, and email addresses and phone numbers, are replaced by codes before the AI analysis. Original uploads are deleted as soon as they have been read. The n8n environment runs in the EU and does not keep execution logs. Drafts are kept until no later than 30 days after delivery. The coding is pseudonymisation, not anonymisation: names in free text that were not provided may slip through.
Article 6. Sub-processors. The customer authorises the sub-processors on the list of sub-processors. The processor notifies the customer of a new sub-processor at least 30 days in advance. The customer may object and then end the agreement. The processor imposes the same obligations on sub-processors as in this agreement. It remains liable to the customer for the performance of its sub-processors' obligations.
Article 7. Assistance. If the processor receives a request from a data subject, it forwards the request to the customer and helps to handle it. The processor also helps the customer with a data protection impact assessment (DPIA) and any prior consultation of the supervisory authority, insofar as this processing is concerned.
Article 8. Personal data breaches. The processor reports a breach involving the customer's data without undue delay, at the latest within 48 hours of discovering it. It provides what it knows about the nature of the breach, the data concerned, the likely consequences and the measures taken. The customer decides whether to notify its supervisory authority.
Article 9. End. At the end, the processor deletes all data within 30 days, unless the law requires it to be kept. If the customer wants the data returned first, the processor sends them on request. By then the customer has already received the second brain.
Article 10. Audit. On request, the processor gives the customer the information needed to show compliance with this agreement. It allows for and contributes to audits, including inspections, by the customer or an auditor the customer appoints. The customer gives at least 30 days' notice of an audit and bears its costs.
Article 11. Liability. Liability under this agreement is governed by article 10 of the terms and conditions.
Article 12. Transfers and customers outside the EU.
- The processor only transfers data to countries outside the EU with an appropriate safeguard, such as an adequacy decision or the European Commission's standard contractual clauses. For Anthropic in the United States, these are the standard contractual clauses in Anthropic's data processing agreement, with the UK addendum for data from the UK.
- If the customer is established in the United Kingdom, this agreement also serves as the contract required by article 28 UK GDPR.
- If the customer is established in the United States, the processor acts as a service provider. The processor shall not (i) sell or share the personal information, (ii) retain, use or disclose the personal information for any purpose other than performing the service described in article 1, or (iii) combine the personal information with personal information it receives from others. It complies with the California Consumer Privacy Act (CCPA) and provides the same level of protection. If it can no longer meet these obligations, it tells the customer, and the customer may take reasonable steps to stop unauthorised use.
Article 13. Acceptance. The customer accepts this agreement at checkout, together with the terms and conditions.
Article 14. Language. This agreement exists in Dutch and English. If the versions differ, the Dutch version prevails.
Sample sentence for the customer's own privacy statement. The customer informs its own clients itself. A sentence that can be used: "I use service providers, including AI services, to support my work. They process data only on my instructions."