DynSolutionZ
Legal

Data processing agreement

Version 3.0 — effective 19 August 2026

This is the data processing agreement referred to in article 28(3) of the General Data Protection Regulation. It is an annex to the licence and subscription terms and forms one agreement with them. Where it conflicts with any other document, this agreement prevails for everything concerning the processing of personal data.

No separate signature is needed: this agreement applies from the moment your subscription starts. If your procurement process requires a signed copy, or your own processor agreement instead, write to us and we will arrange it.

1. Roles

You are the controller. You determine why and how the personal data described in article 3 is processed. DynSolutionz is the processor and processes that data only on your behalf.

There is one exception, set out in article 12: for our own customer administration — your contact details, invoicing, quotes and the security of our own systems — we are the controller ourselves, and our privacy statement applies rather than this agreement.

2. Subject, nature, purpose and duration

We process personal data solely to provide DynBrowser and the associated online services: licence and seat administration, the customer portal, support, and the server-side features described in article 12 of the licence terms. Processing consists of collecting, storing, consulting, transmitting, correcting and deleting.

This agreement runs for as long as your subscription runs, and afterwards for as long as we still hold personal data of yours, until article 11 has been fully carried out.

3. Data subjects and personal data

Data subjects are the people within your organisation who use DynBrowser or the customer portal, and the contact persons you register with us. The categories of personal data are:

CategoryWhat it contains
AccountsName, e-mail address, preferred language, password stored as a one-way hash, two-factor secret and recovery codes where enabled, permissions and admin rights.
SessionsPortal and console login records: time, IP address, browser type, and the hash of the session token.
InstallationsHashed machine identifier, machine name, application version and channel, and the Dynamics 365 environment domain, linked to the signed-in user's e-mail address.
UsageMinutes of use per user per day and per hour, online status, and which parts of the application were used.
Error reportsHashed machine identifier, application version and a scrubbed error description, filtered before sending to remove e-mail addresses, URLs, paths, IP addresses, identifiers and tokens.
SupportName and e-mail of the person reporting, the text of the report and its comments, any files attached, and the page, operating system and application version it came from.
Content authorshipThe e-mail address recorded against planning changes, scenarios, planner notes, Document Designer templates, images and themes — that is, who changed what and when.
DistributionThe recipient of a download link and the record of downloads, including IP address.
Activity logLogins, password resets, user management, downloads and administrative actions, with actor, IP address and browser type.
ArcadeAnonymous play statistics with a hashed machine identifier; and, only where the user switched it on, a leaderboard entry with their name and score.

We process no special categories of personal data as defined in article 9 GDPR, and we ask you not to enter any into the software.

4. Instructions

We process personal data only on your documented instructions. The licence terms, this agreement and your use of the software's own settings together constitute those instructions. We process no personal data for our own purposes, and we do not sell it or use it for advertising.

Where the law obliges us to process data beyond your instructions, we will tell you first, unless that same law forbids it. Where in our view an instruction breaches data protection law, we will tell you without delay.

5. Confidentiality

Everyone we authorise to process personal data is bound to confidentiality, contractually or by statute, and gets access only where their work requires it.

6. Security

We take appropriate technical and organisational measures under article 32 GDPR. As at the effective date of this agreement, they include:

  • encryption of all traffic in transit (TLS);
  • passwords stored only as strong one-way hashes (PBKDF2-SHA256, 210,000 iterations), and session tokens stored only as hashes, so a copy of the database hands out no live sessions;
  • optional two-factor authentication for portal and console accounts, with the secrets encrypted at rest, plus lockout after repeated failed logins and rate limiting per IP address;
  • licence tickets signed with an ECDSA P-256 key, so a licence decision cannot be forged;
  • strict separation per company on every query, so one customer's data is not reachable from another's account;
  • error reports scrubbed on the customer's own machine before they are sent, not after they arrive;
  • hardened web responses (content security policy, host allowlist, HSTS) and no external scripts, fonts, analytics or content delivery networks — our pages load nothing from third parties;
  • daily backups that are verified after they are written, kept with restricted file permissions on the same European infrastructure;
  • restricted access to production systems, limited to those who need it to operate the service.

We may change these measures as the state of the art moves on, provided the level of protection does not fall.

7. Sub-processors

You give us general authorisation to engage sub-processors. We impose on each of them, by contract, obligations equivalent to those in this agreement, and we remain fully liable to you for their performance. Our sub-processors are:

Sub-processorPurposeLocation
STRATO AGServer hosting and storage of the application and its database and backupsGermany (EU)
STRATO AGOutgoing transactional e-mail (activation, password reset, notifications, quotes and invoices)Germany (EU)
Mollie B.V.Online payment of invoices, where you choose to pay that way. Mollie is an independent controller for the payment data it handles.Netherlands (EU)

We will tell you at least thirty days before we add or replace a sub-processor. Where you have reasonable grounds to object, tell us within those thirty days; if we cannot resolve it, you may terminate the subscription with effect from the date the change takes effect, and we refund the unused remainder of the period you have paid for.

8. Assistance

Taking into account the nature of the processing, we assist you with: requests from data subjects for access, rectification, erasure, restriction, objection or portability; your obligations to keep processing secure; the reporting of personal data breaches; and any data protection impact assessment or prior consultation.

Where a data subject approaches us directly, we do not answer on your behalf: we forward the request to you without undue delay. The customer portal and the admin console already let you inspect, correct and delete most of this data yourself; where they do not, we help within a reasonable time. Assistance is included in your subscription, unless a request calls for disproportionate effort, in which case we will agree the cost with you in advance.

9. Personal data breaches

We notify you without undue delay, and in any event within forty-eight hours, after becoming aware of a personal data breach affecting your data. The notification describes what happened, which categories and roughly how many people and records are involved, the likely consequences, the measures we have taken, and a contact point. Reporting to the supervisory authority and to data subjects is yours to do, as controller; we give you what you need for it.

10. Audit and information

On request we give you the information you reasonably need to demonstrate that we comply with article 28 GDPR. You may have an audit carried out once per calendar year, and additionally after a personal data breach affecting your data, by an independent expert bound to confidentiality, with at least thirty days' notice, during business hours and without disrupting our operations or exposing other customers' data. You bear the cost, unless the audit shows a material failure on our part, in which case we do.

11. Return and deletion

After the subscription ends we keep your data available for export for thirty days and delete it within sixty days. Backups containing it age out within ninety days. We keep data for longer only where the law requires it, and then only for that purpose and for that period — invoicing records, for instance, which we must keep for seven years under Dutch tax law.

12. Where we are the controller

For our own customer administration we are the controller rather than your processor. That covers the contact details of the people we deal with, quotes, invoices and payments, the correspondence we have with you, and the security and abuse prevention of our own systems. That processing is described in our privacy statement.

13. Transfers outside the EEA

We do not transfer personal data outside the European Economic Area. All processing under this agreement takes place on European infrastructure, with the sub-processors named in article 7. Should that ever change, we will tell you in advance under article 7 and put a valid transfer mechanism in place.

14. Liability, changes and law

The liability provisions of the licence and subscription terms apply to this agreement, save where mandatory law provides otherwise. Where those provisions and this agreement conflict on the processing of personal data, this agreement prevails.

We may amend this agreement where legislation, supervisory guidance or the service requires it. A new version is published here with its own version number and effective date and announced at least thirty days in advance. Dutch law applies.

15. Who we are

DynSolutionz
NL

Privacy questions, a data subject request, or a signed copy of this agreement: info@dynsolutionz.com. See also the licence and subscription terms and the privacy statement.

DynSolutionZ
Privacy Terms Licence Processing agreement Customer portal
© 2026 DynSolutionz