Data Processing Agreement
Last updated: 20 augustus 2026
Table of contents
This Data Processing Agreement forms part of the Agreement between EventDock B.V. ("EventDock") and the Customer and is applicable as soon as EventDock processes personal data on behalf of the Customer in the execution of the Agreement.
Data Controller: The Customer determines the purpose and the means of the camera surveillance: where the cameras are positioned, what is captured on screen, who is permitted to view the footage, and for how long footage is retained. The Customer is therefore the data controller within the meaning of Article 4(7) GDPR.
Data Processor: EventDock processes personal data exclusively by order of and in accordance with instructions from the Customer and is therefore the data processor within the meaning of Article 4(8) GDPR.
Own processing by EventDock: For data that EventDock processes for its own purposes (such as customer administration, invoicing, contact, and website use), EventDock itself is the data controller. The Privacy Policy applies to such processing, and not this Data Processing Agreement.
Subject Matter: The supply, installation, management and (optional) monitoring of temporary camera and security systems, including the storage and provision of camera footage.
Nature of the processing: Recording, storing, transmitting (streaming), viewing, exporting, erasing and securing of visual material and associated metadata.
Types of personal data: - Visual material of persons who come within view of the cameras - Associated metadata such as date, time and location of recording - In the case of ANPR applications: license plates and vehicle characteristics - Access and log files of users of the management portal
Categories of data subjects: Visitors to the location, employees and subcontractors of the Client, passers-by and, in the case of ANPR, holders of registered vehicles.
Duration: This Data Processing Agreement applies for as long as EventDock processes personal data for the Client and ends after completion of the Rental Period and erasure of the data in accordance with article 10.
3.1. EventDock shall process personal data exclusively on the basis of written instructions from the Client and not for its own purposes.
3.2. Instructions are established in the Agreement, the order confirmation, and the settings selected in the management portal.
3.3. EventDock shall inform the Client without delay if, in EventDock's opinion, an instruction is in conflict with the GDPR or other applicable legislation.
3.4. The Client guarantees that there is a valid legal basis for the camera surveillance, that a legitimate interest has been weighed, that a DPIA has been performed where necessary, and that data subjects at the location are clearly informed about the camera surveillance.
3.5. EventDock does not process special categories of personal data, unless this inevitably arises from video recordings; the Client is responsible for limiting the camera footage to what is necessary.
4.1. EventDock undertakes to maintain the confidentiality of all personal data it processes on behalf of the Customer.
4.2. Employees and engaged third parties of EventDock are contractually bound to confidentiality and are granted access only insofar as necessary for their tasks (need-to-know).
4.3. The duty of confidentiality remains in force even after termination of the Agreement.
EventDock shall implement appropriate technical and organisational measures in accordance with Article 32 GDPR, including:
- Encrypted connections (TLS) for streaming and accessing footage
- Encrypted storage of visual material
- Account security with unique login credentials and role-based permissions
- Logging of access to footage and system settings
- Physical security of equipment, locks and housing of masts and cases
- Firmware and software updates on the camera systems
- Password policy and authorisation management at EventDock
- Periodic checks of the configuration before and after each rental period
The Client is responsible for the careful management of its own accounts, limiting the circle of users and the timely withdrawal of access for departed employees.
6.1. The Customer grants EventDock general permission to engage sub-processors for hosting, storage, payment processing and communication.
6.2. EventDock shall impose at least the same obligations on sub-processors as those set out in this Data Processing Agreement.
6.3. A current list of sub-processors can be found at the bottom of this page. EventDock shall inform the Customer in advance of intended changes, so that the Customer may object to them.
6.4. If an objection remains and no reasonable alternative can be found, the Customer may terminate the relevant part of the Agreement without penalty.
7.1. Camera images are stored and processed within the European Economic Area.
7.2. For supporting services, limited transfer outside the EEA may occur (for example, payment or e-mail services). In such cases, EventDock bases the transfer on an adequacy decision or on the standard contractual clauses of the European Commission, with additional measures where necessary.
7.3. EventDock does not transfer personal data to authorities outside the EEA, unless it is legally obliged to do so; in that case, EventDock shall inform the Customer as soon as this is permitted.
8.1. Requests from data subjects (access, rectification, erasure, restriction or objection) shall be handled by the Customer as the controller.
8.2. If EventDock receives a request concerning the data of the Customer, EventDock shall refer the data subject to the Customer and shall inform the Customer thereof within 3 working days.
8.3. EventDock shall provide reasonable cooperation in the execution of a request, for example by searching for, exporting or deleting image fragments. For extensive manual tasks, EventDock may charge costs at the applicable hourly rate, after prior quotation.
9.1. EventDock shall inform the Customer without undue delay and in any event within 24 hours after the discovery of a personal data breach.
9.2. The notification shall contain, insofar as known: the nature of the breach, the categories of data and data subjects concerned, the likely consequences and the measures taken or proposed.
9.3. EventDock shall not itself make any notification to the Dutch Data Protection Authority (Dutch Data Protection Authority (Autoriteit Persoonsgegevens)) or to data subjects on behalf of the Customer, unless otherwise agreed in writing. The Customer shall assess whether notification is required.
9.4. EventDock shall support the Customer in the investigation, mitigation of consequences and documentation of the incident.
10.1. Camera images shall be retained in accordance with the retention period set by the Customer. The standard period is 7 days; the legal guideline for camera images is a maximum of 4 weeks, unless images are required for the handling of an incident.
10.2. After the end of the Rental Period, all camera images and associated metadata shall be permanently deleted within 30 days at the latest, unless the Customer requests earlier deletion or an export in writing.
10.3. At the request of the Customer, EventDock shall provide an export in a common format prior to deletion.
10.4. Equipment shall be wiped after return before it is issued again.
10.5. Data that EventDock is legally required to retain (such as invoicing data) shall remain outside this obligation to delete.
11.1. EventDock shall, upon request, make information available with which the Customer can demonstrate that Article 28 GDPR is being complied with, such as an overview of the security measures taken and the list of sub-processors.
11.2. The Customer may have an audit performed by an independent expert a maximum of once per year, after a notice period of at least 30 days and during office hours.
11.3. The costs of the audit shall be borne by the Customer, unless the audit reveals that EventDock is in breach of its compliance with this Data Processing Agreement.
11.4. In the event of an established deficiency, EventDock shall rectify this within a reasonable period.
12.1. The limitations of liability set out in the General Terms and Conditions of EventDock shall apply to this Data Processing Agreement, to the extent permitted by the GDPR.
12.2. In the event of any conflict between this Data Processing Agreement and the General Terms and Conditions, this Data Processing Agreement shall prevail insofar as it concerns the processing of personal data.
12.3. This Data Processing Agreement is governed by Dutch law. Disputes shall be submitted to the competent court in the district where EventDock is established.
12.4. Do you wish to receive a signed version of this Data Processing Agreement? Please request one via privacy@eventdock.nl; we will then send a copy in the name of your organisation.
Questions about this Data Processing Agreement? Please contact us:
EventDock B.V. Dortherweg 29 7214 PS Epse Chamber of Commerce number: 42095557 Email: privacy@eventdock.nl Phone: +31 85 505 5059 Website: www.eventdock.nl
Overview of Sub-processors
These parties may process personal data when providing our services.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase (EU region) | Hosting of database, accounts, and application logic | EU/EEA |
| Cloud storage camera footage (EU region) | Storage and playback of footage for monitoring packages | EU/EEA |
| Stripe | Payment processing (no camera footage) | EU/EEA, US (EU Standard Contractual Clauses) |
| Resend | Sending transactional email (no camera footage) | EU/EEA, US (EU Standard Contractual Clauses) |