Data Processing Agreement (DPA)
Version 2026-07-09 (draft)
This English text is a translation provided for convenience only. The Dutch version of this agreement is legally binding; in the event of any discrepancy, the Dutch text prevails. This agreement is governed by Dutch law and the GDPR.
This data processing agreement forms part of the agreement on the use of the CarwashManager platform and governs how we, as processor, handle personal data.
1. Parties and roles
CarwashManager — Sportlaan 22, 3851 CD Ermelo, Chamber of Commerce 73612537. For a direct car wash we are the processor and the car wash is the controller. For white-label via an agency, the agency is the processor and we are the sub-processor; the car wash remains the ultimate controller.
2. Purpose and data
We process solely for the delivery of the platform: wash tickets and discount codes, customer and transaction records, email marketing (opt-in), invoicing and optionally licence-plate recognition. This concerns the name, email address, postcode, licence plate and transaction history of the car wash's customers. No special categories of personal data are knowingly processed.
If the controller uses the optional licence-plate recognition, it is responsible for a valid legal basis and for informing data subjects (for example via a camera surveillance sticker at the entrance and its privacy statement). We process the licence plate solely on instruction: the camera images are processed on the spot and deleted immediately afterwards — only the licence plate and the timestamp are kept. Only when setting up a camera at a new location may we temporarily keep a limited number of images (only the licence-plate section, not linked to persons) to fine-tune recognition; after that we delete them. We delete licence plates on request or, if the controller sets a retention period, after it expires.
3. Security (art. 32)
- Tenant isolation at database level (row level security).
- Encryption of sensitive keys (AES-256-GCM) and transport via TLS.
- Access on a need-to-know basis, with audit logging.
- Encrypted, off-site back-ups; rate limiting on public endpoints.
4. Sub-processors
We engage sub-processors; the current list is on the sub-processor list. On any change we inform the controller, who may object with reasons.
5. Data breaches
We report a data breach without delay and no later than 48 hours after discovery to the controller, so that it can meet its notification obligation (within 72 hours) in time.
6. Rights of data subjects
We assist the controller with requests from data subjects (access, rectification, erasure, data portability) through the functionality of the platform. Requests that reach us directly we forward to the controller.
7. Retention and deletion
After termination we delete or return the personal data, subject to statutory retention obligations (such as the tax retention obligation for invoices). Wash tickets and codes have a grace period (60 days by default) during which they remain redeemable.
8. Transfer outside the EEA
Data is in principle processed within the EEA. For sub-processors outside the EEA, appropriate safeguards apply (EU standard contractual clauses or a valid adequacy framework).
This is a draft version. Questions? Email info@carwashmanager.app.