Data Processing Agreement
Version 2026-09-03
DiveOpsHub Data Processing Agreement
This data processing agreement ("Data Processing Agreement") belongs to and forms part of the agreement between:
- Controller: the Customer (the dive school/company) that uses DiveOpsHub ("Controller"); and
- Processor: IJsselmuiden Management B.V., trading under the name DiveOpsHub, established in Hillegom, the Netherlands (DiveOpsHub).
Article 1 — Concepts
Concepts such as personal data, processing, data subject, personal data breach, sub-processor and supervisory authority have the meaning set out in the General Data Protection Regulation (GDPR).
Article 2 — Subject matter, nature and purpose of the processing
2.1 DiveOpsHub processes personal data solely for the purpose of providing the Service to the Controller, as further described in Annex 1. 2.2 The nature of the processing concerns storing, consulting, editing, transmitting and deleting data within the Service (including customer administration, rental, point of sale/invoicing, courses, maintenance, newsletter, customer portal). 2.3 The purpose is to facilitate the Controller's business operations via the Service. 2.4 DiveOpsHub processes the personal data solely on the basis of documented instructions from the Controller, including this Data Processing Agreement, unless a legal obligation provides otherwise (in which case DiveOpsHub notifies this in advance, unless that law prohibits it). 2.5 DiveOpsHub does not process the data for its own purposes and does not sell it.
Article 3 — Duration
3.1 This Data Processing Agreement applies for as long as DiveOpsHub processes personal data for the Controller in the context of the Service. 3.2 Obligations that by their nature continue (such as confidentiality) remain in force after termination.
Article 4 — Categories of data subjects and personal data
The categories of data subjects and (special categories of) personal data are set out in Annex 1.
Article 5 — DiveOpsHub's obligations
5.1 DiveOpsHub processes the data solely in accordance with the Controller's instructions. 5.2 DiveOpsHub ensures that persons with access to the data are bound by confidentiality. 5.3 DiveOpsHub provides the Controller with reasonable assistance in fulfilling its obligations under the GDPR, including requests from data subjects (Article 8), security (Article 6), personal data breaches (Article 7) and data protection impact assessments (DPIAs). 5.4 DiveOpsHub informs the Controller if, in its opinion, an instruction infringes the GDPR or other legislation.
Article 6 — Security
6.1 DiveOpsHub takes appropriate technical and organisational measures as referred to in Article 32 GDPR to secure the data against loss or unlawful processing. An overview is set out in Annex 2. 6.2 The measures are aligned with the state of the art, the costs of implementation and the nature and risks of the processing. DiveOpsHub may update measures as long as the level of protection remains at least equivalent.
Article 7 — Personal data breaches
7.1 DiveOpsHub informs the Controller without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach concerning the Controller's data. 7.2 In doing so, DiveOpsHub provides the information the Controller reasonably needs to comply with its notification obligation to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and (where applicable) the data subjects. 7.3 The notification to the supervisory authority and/or data subjects is the Controller's responsibility, unless agreed otherwise.
Article 8 — Rights of data subjects
8.1 Taking into account the nature of the processing, DiveOpsHub provides reasonable assistance so that the Controller can comply with requests from data subjects (access, rectification, erasure, restriction, portability, objection). 8.2 If DiveOpsHub receives a request directly from a data subject, it refers the data subject to the Controller or notifies the Controller, and does not handle it independently.
Article 9 — Sub-processors
9.1 The Controller gives DiveOpsHub general authorisation to engage sub-processors for the performance of the Service. The sub-processors currently engaged are set out in Annex 3. 9.2 DiveOpsHub imposes on sub-processors at least the same obligations as in this Data Processing Agreement and remains responsible towards the Controller for their actions. 9.3 DiveOpsHub informs the Controller of intended changes to sub-processors, so that the Controller can object to them. In the event of a justified objection, the parties consult; if this does not lead to a solution, the Controller may terminate the relevant service(s).
Article 10 — Transfer outside the EEA
10.1 DiveOpsHub processes the data in principle within the European Economic Area (EEA). 10.2 If a transfer to a country outside the EEA takes place, DiveOpsHub ensures an appropriate transfer mechanism in accordance with Chapter V GDPR (such as an adequacy decision or the EU standard contractual clauses).
Article 11 — Audits
11.1 On request, DiveOpsHub makes available to the Controller the information necessary to demonstrate compliance with this Article 28 GDPR. 11.2 The Controller may carry out (or have carried out) an audit at most once a year, after reasonable notice and without unnecessarily disrupting operations. The reasonable costs of this are borne by the Controller, unless the audit reveals a material shortcoming on the part of DiveOpsHub.
Article 12 — Return and deletion
12.1 At the end of the Service, DiveOpsHub deletes the personal data or, on request, returns it, at the Controller's choice, and deletes existing copies, subject to statutory retention obligations. 12.2 The Controller is given a reasonable period of 30 days to make an export itself.
Article 13 — Liability
13.1 The liability regime from DiveOpsHub's Terms of Service applies to this Data Processing Agreement, without prejudice to mandatory law and Article 82 GDPR.
Article 14 — Final provisions
14.1 In the event of a conflict between this Data Processing Agreement and the Terms of Service, this Data Processing Agreement prevails insofar as it concerns the processing of personal data. 14.2 Dutch law applies to this Data Processing Agreement.
Annex 1 — Overview of the processing
- Categories of data subjects: clients/students of the Controller, staff/users of the Controller, contact persons.
- Categories of personal data: name, address, email, phone, customer/invoicing data, purchase and rental history, equipment/service data, fill-card/balance data, login credentials, certification data. Dive-medical/health data, if entered by the Controller, are special categories of personal data; these are processed only on a valid legal basis.
- Purpose: administration and business operations of the Controller via the Service.
- Retention period: for as long as the account exists and thereafter in accordance with Article 12 and statutory retention periods (e.g. the 7-year tax retention obligation for invoice data).
Annex 2 — Security measures (indicative)
- Encrypted connections (HTTPS/TLS) for all access to the Service.
- Strict separation of data per customer (multi-tenant isolation).
- Access management based on roles and permissions; passwords stored encrypted.
- Login attempt limiting and security headers against misuse.
- Regular back-ups and recovery procedures.
- Security updates and periodic review of the code/dependencies.
- Logging and monitoring of relevant events.
- Hosting/data-centre location: data centres of Hetzner Online GmbH in Germany and/or Finland (within the EEA).
Annex 3 — Sub-processors
| Sub-processor | Service | Location |
|---|---|---|
| Mollie B.V. | Payment processing (iDEAL/SEPA direct debit) | Netherlands/EEA |
| Hetzner Online GmbH | Hosting of the Service, data storage and email sending | Germany / Finland (EEA) |