Data processing agreement
This is the data processing agreement referred to in article 28(3) of the General Data Protection Regulation. It is an annex to the licence and subscription terms and forms one agreement with them. Where it conflicts with any other document, this agreement prevails for everything concerning the processing of personal data.
No separate signature is needed: this agreement applies from the moment your subscription starts. If your procurement process requires a signed copy, or your own processor agreement instead, write to us and we will arrange it.
1. Roles
You are the controller. You determine why and how the personal data described in article 3 is processed. DynSolutionz is the processor and processes that data only on your behalf.
There is one exception, set out in article 12: for our own customer administration — your contact details, invoicing, quotes and the security of our own systems — we are the controller ourselves, and our privacy statement applies rather than this agreement.
2. Subject, nature, purpose and duration
We process personal data solely to provide DynBrowser and the associated online services: licence and seat administration, the customer portal, support, and the server-side features described in article 12 of the licence terms. Processing consists of collecting, storing, consulting, transmitting, correcting and deleting.
This agreement runs for as long as your subscription runs, and afterwards for as long as we still hold personal data of yours, until article 11 has been fully carried out.
3. Data subjects and personal data
Data subjects are the people within your organisation who use DynBrowser or the customer portal, and the contact persons you register with us. The categories of personal data are:
| Category | What it contains |
|---|---|
| Accounts | Name, e-mail address, preferred language, password stored as a one-way hash, two-factor secret and recovery codes where enabled, permissions and admin rights. |
| Sessions | Portal and console login records: time, IP address, browser type, and the hash of the session token. |
| Installations | Hashed machine identifier, machine name, application version and channel, and the Dynamics 365 environment domain, linked to the signed-in user's e-mail address. |
| Usage | Minutes of use per user per day and per hour, online status, and which parts of the application were used. |
| Error reports | Hashed machine identifier, application version and a scrubbed error description, filtered before sending to remove e-mail addresses, URLs, paths, IP addresses, identifiers and tokens. |
| Support | Name and e-mail of the person reporting, the text of the report and its comments, any files attached, and the page, operating system and application version it came from. |
| Content authorship | The e-mail address recorded against planning changes, scenarios, planner notes, Document Designer templates, images and themes — that is, who changed what and when. |
| Distribution | The recipient of a download link and the record of downloads, including IP address. |
| Activity log | Logins, password resets, user management, downloads and administrative actions, with actor, IP address and browser type. |
| Arcade | Anonymous play statistics with a hashed machine identifier; and, only where the user switched it on, a leaderboard entry with their name and score. |
We process no special categories of personal data as defined in article 9 GDPR, and we ask you not to enter any into the software.
4. Instructions
We process personal data only on your documented instructions. The licence terms, this agreement and your use of the software's own settings together constitute those instructions. We process no personal data for our own purposes, and we do not sell it or use it for advertising.
Where the law obliges us to process data beyond your instructions, we will tell you first, unless that same law forbids it. Where in our view an instruction breaches data protection law, we will tell you without delay.
5. Confidentiality
Everyone we authorise to process personal data is bound to confidentiality, contractually or by statute, and gets access only where their work requires it.
6. Security
We take appropriate technical and organisational measures under article 32 GDPR. As at the effective date of this agreement, they include:
- encryption of all traffic in transit (TLS);
- passwords stored only as strong one-way hashes (PBKDF2-SHA256, 210,000 iterations), and session tokens stored only as hashes, so a copy of the database hands out no live sessions;
- optional two-factor authentication for portal and console accounts, with the secrets encrypted at rest, plus lockout after repeated failed logins and rate limiting per IP address;
- licence tickets signed with an ECDSA P-256 key, so a licence decision cannot be forged;
- strict separation per company on every query, so one customer's data is not reachable from another's account;
- error reports scrubbed on the customer's own machine before they are sent, not after they arrive;
- hardened web responses (content security policy, host allowlist, HSTS) and no external scripts, fonts, analytics or content delivery networks — our pages load nothing from third parties;
- daily backups that are verified after they are written, kept with restricted file permissions on the same European infrastructure;
- restricted access to production systems, limited to those who need it to operate the service.
We may change these measures as the state of the art moves on, provided the level of protection does not fall.
7. Sub-processors
You give us general authorisation to engage sub-processors. We impose on each of them, by contract, obligations equivalent to those in this agreement, and we remain fully liable to you for their performance. Our sub-processors are:
| Sub-processor | Purpose | Location |
|---|---|---|
| STRATO AG | Server hosting and storage of the application and its database and backups | Germany (EU) |
| STRATO AG | Outgoing transactional e-mail (activation, password reset, notifications, quotes and invoices) | Germany (EU) |
| Mollie B.V. | Online payment of invoices, where you choose to pay that way. Mollie is an independent controller for the payment data it handles. | Netherlands (EU) |
We will tell you at least thirty days before we add or replace a sub-processor. Where you have reasonable grounds to object, tell us within those thirty days; if we cannot resolve it, you may terminate the subscription with effect from the date the change takes effect, and we refund the unused remainder of the period you have paid for.
8. Assistance
Taking into account the nature of the processing, we assist you with: requests from data subjects for access, rectification, erasure, restriction, objection or portability; your obligations to keep processing secure; the reporting of personal data breaches; and any data protection impact assessment or prior consultation.
Where a data subject approaches us directly, we do not answer on your behalf: we forward the request to you without undue delay. The customer portal and the admin console already let you inspect, correct and delete most of this data yourself; where they do not, we help within a reasonable time. Assistance is included in your subscription, unless a request calls for disproportionate effort, in which case we will agree the cost with you in advance.
9. Personal data breaches
We notify you without undue delay, and in any event within forty-eight hours, after becoming aware of a personal data breach affecting your data. The notification describes what happened, which categories and roughly how many people and records are involved, the likely consequences, the measures we have taken, and a contact point. Reporting to the supervisory authority and to data subjects is yours to do, as controller; we give you what you need for it.
10. Audit and information
On request we give you the information you reasonably need to demonstrate that we comply with article 28 GDPR. You may have an audit carried out once per calendar year, and additionally after a personal data breach affecting your data, by an independent expert bound to confidentiality, with at least thirty days' notice, during business hours and without disrupting our operations or exposing other customers' data. You bear the cost, unless the audit shows a material failure on our part, in which case we do.
11. Return and deletion
After the subscription ends we keep your data available for export for thirty days and delete it within sixty days. Backups containing it age out within ninety days. We keep data for longer only where the law requires it, and then only for that purpose and for that period — invoicing records, for instance, which we must keep for seven years under Dutch tax law.
12. Where we are the controller
For our own customer administration we are the controller rather than your processor. That covers the contact details of the people we deal with, quotes, invoices and payments, the correspondence we have with you, and the security and abuse prevention of our own systems. That processing is described in our privacy statement.
13. Transfers outside the EEA
We do not transfer personal data outside the European Economic Area. All processing under this agreement takes place on European infrastructure, with the sub-processors named in article 7. Should that ever change, we will tell you in advance under article 7 and put a valid transfer mechanism in place.
14. Liability, changes and law
The liability provisions of the licence and subscription terms apply to this agreement, save where mandatory law provides otherwise. Where those provisions and this agreement conflict on the processing of personal data, this agreement prevails.
We may amend this agreement where legislation, supervisory guidance or the service requires it. A new version is published here with its own version number and effective date and announced at least thirty days in advance. Dutch law applies.
15. Who we are
NL
Privacy questions, a data subject request, or a signed copy of this agreement: info@dynsolutionz.com. See also the licence and subscription terms and the privacy statement.