Data processing terms
Version 11 September 2026
These terms describe processing of customer workspace data by De Bonte Koning for the organisation using Trakkit.
Parties, scope and instructions
The customer organisation identified in the workspace and subscription is the controller; De Bonte Koning is the processor for workspace data. These terms form part of the Trakkit service terms. An authorised customer can request a signed copy identifying both parties and any additional instructions at privacy@trakkit.eu. Customer instructions comprise the service agreement, workspace settings and authorised requests. We process only on documented instructions, including for transfers, unless applicable law requires otherwise; we inform the customer of that requirement unless prohibited.
Processing description
The purpose is hosting and operating recurring supplier reviews: storing forms and supplier information, inviting reviewers, collecting and comparing responses, generating requested reports and exports, supporting users and recovering the service. Data subjects are customer users, reviewers and supplier/business contacts. Data includes names, business emails, organisation and role, supplier context, scores, comments, review history, delivery and access records. Optional AI processes selected instructions and form or review content only on request. Special-category and criminal-offence data are outside the intended service scope. Processing continues for the service and applicable return/deletion period.
Confidentiality and security
We restrict access to authorised people who need it to operate or support the service and are subject to confidentiality. We maintain technical and organisational measures appropriate to the processing, described on the Security & data page, including authentication, permissions, tenant checks, encrypted transport and backups. We inform the customer if an instruction appears to infringe data-protection law.
Subprocessors and transfers
The customer gives general authorisation for Railway (hosting/storage), Lettermint (transactional email) and OpenAI (only when optional AI is requested). These providers and the location limits are listed on the security page. We impose applicable data-protection duties on subprocessors and remain responsible for their performance of those duties. Before adding or replacing a workspace subprocessor, we notify the customer with at least 30 days to raise a reasoned data-protection objection. We work to resolve it before the change; if no workable solution exists, the customer may stop the affected processing and end the affected service. Any restricted international transfer must use an applicable lawful transfer mechanism; an Amsterdam workload alone is not that mechanism.
Assistance and incidents
We assist the customer, taking account of the nature of processing and available information, with data-subject requests, security obligations, breach response, impact assessments and supervisory consultations. We notify the customer without undue delay after becoming aware of a personal-data breach, provide available details about its nature, affected records and people, likely consequences and response, and supplement information as the investigation progresses. The customer decides its notifications to people and authorities.
Return, deletion and evidence
The customer can export results during active access and the 30-day read/export window after expiry. Expiry alone does not instruct deletion. At the customer’s verified request on ending the service, we return or delete workspace personal data as instructed and delete remaining copies unless law requires retention. We confirm the scope, active-system completion and the applicable backup expiry; if a backup is restored, the deletion instruction is reapplied. We make information needed to demonstrate these obligations available and allow proportionate audits and inspections by the customer or its mandated auditor, with confidentiality and safeguards for other customers.
Customer responsibilities and precedence
The customer is responsible for a lawful basis, appropriate notices to users and reviewers, minimising personal data, managing its users and instructions, and protecting exports and invitation links. These processing terms take precedence over conflicting service terms for processing of workspace personal data. Our own billing, security and business-contact administration is described separately in the privacy notice.