If you work with your customers’ personal data, you want to be sure it is properly arranged. Especially when your professional association, your sector or a business client sets requirements, questions soon follow: is there a data processing agreement, where is the data stored, and how is security organised? This article brings all the answers together in one place, so you can forward them or use them in your own privacy statement.
1. Arrange the data processing agreement in a few minutes #
Under the GDPR you are the controller for the data of your contacts and customers, and we are the processor. You record the arrangements for that in a data processing agreement, and it is ready for you:
- Go to mijn.autorespond.nl/verwerkersovereenkomst.
- Enter your company details, including the contact person we should reach if anything ever happens with the data.
- You immediately receive the full data processing agreement in your company’s name, ready for signing.
The agreement states exactly what we process for you (annex 1), which security measures go with that and which rights you have, including an annual right of audit.
2. How security is organised #
Autorespond is a fully managed platform. We take care of updates, maintenance and security centrally, and no custom or third-party code can be installed on your environment. That keeps the attack surface much smaller than on a website you have to maintain yourself. On top of that, the measures recorded in the data processing agreement apply:
- Encrypted connections (TLS) and encrypted data storage.
- Access control with limited rights: everyone can only reach what is needed for their work.
- Firewalls and network segmentation.
- Daily backups in a separate storage location.
- Logging and monitoring, and security updates for the platform and the underlying software.
You contribute to the security of your environment too. Switch on two-factor authentication for your administration, and give every employee their own account with a suitable role instead of a shared login.
3. Where your data is stored #
Processing takes place within the European Economic Area. Only if a service outside it is needed does that happen on the basis of a valid transfer mechanism from the GDPR, such as standard contractual clauses or an adequacy decision. You can always see which parties we engage, including their country of establishment, at mijn.autorespond.nl/subverwerkers.
4. What happens in the event of a data breach #
If we establish a breach involving personal data, we inform you within 48 hours through the contact person named in your data processing agreement, telling you what happened, which data is involved and which measures have been taken. Worth knowing: as the controller, you report to the supervisory authority and to the data subjects yourself. We supply all the information you need for that.
5. When your subscription ends #
If you stop using Autorespond, the choice is yours: all your data as an export in a common format, or deletion. That happens within 30 days after the end of your subscription. Data in backups then disappears automatically through the regular backup rotation and is no longer available after 30 days at the latest.
6. Strict requirements from your professional association or sector #
Do you work in a sector with additional requirements, for example from a professional association, healthcare or a large business client? Send the checklist or standard you have to comply with to support, and we will go through it point by point with you, so you get a clear answer for each item on how it is arranged at Autorespond.
And if specific requirements are set for the configuration or security of your environment, we can support you there as well with additional tailored measures. Depending on what is needed, a fee may apply; we discuss that in advance, so you are never caught out.
7. Worth knowing #
- You can find the terms and conditions at mijn.autorespond.nl/algemene-voorwaarden-voor-het-nieuwe-autorespond.
- For your own visitors you arrange the cookie and privacy side in your environment yourself, for example with your own privacy statement and a cookie banner. The article below explains how to link to those.
- If you use AI tools yourself alongside your Autorespond environment, separate GDPR considerations apply there; there is a separate article about that as well.