Data Processing Agreement
Annex to the Terms and Conditions for Clients of Blackbear B.V.
Last updated: 1 August 2026
This Data Processing Agreement forms part of the Terms and Conditions for Clients and is accepted by the Client together with them. Under it, Blackbear B.V. (“Blackbear”) processes personal data as processor on behalf of the Client, which is the controller. Capitalised terms have the meaning given in the Terms and Conditions for Clients; terms from the GDPR (Regulation (EU) 2016/679) have the meaning given there.
In this Data Processing Agreement, Project Content means: the data entered, uploaded or exchanged via the Platform within an Initiative, a SOW or a Project, to the extent that it contains personal data. Platform data, including account and profile data and the data for the financial settlement, does not fall under this; for that, Blackbear is itself the controller.
Article 1. Subject matter
Blackbear processes the Project Content solely for the purposes of the Platform Services. The nature, the purpose and the duration of the processing, the types of personal data and the categories of data subjects are described in Annex 1. In the event of a conflict with the other provisions of the Terms and Conditions for Clients regarding the processing of personal data, this Data Processing Agreement prevails.
Article 2. Instructions
Blackbear processes the Project Content solely on the basis of the documented instructions of the Client. The use of the Platform by the Client and its Users counts as an instruction. Blackbear does not process the Project Content for its own purposes, unless a statutory obligation requires it to do so, and notifies the Client if, in its opinion, an instruction conflicts with the GDPR. The Client warrants that it is entitled to submit the Project Content and does not submit special categories of personal data within the meaning of Article 9 GDPR, unless the Parties agree this in writing.
Article 3. Confidentiality
Blackbear ensures that the persons it involves in the processing are bound to confidentiality of the Project Content.
Article 4. Security
Blackbear takes appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. The measures are described in Annex 3.
Article 5. Sub-processors
The Client grants Blackbear general authorisation for engaging sub-processors. The current sub-processors are listed in Annex 2. Blackbear informs the Client in advance of an intended addition or replacement of a sub-processor, so that the Client can object to it. Blackbear imposes on each sub-processor the same data protection obligations as in this Data Processing Agreement, and remains liable towards the Client for the performance by the sub-processor.
Article 6. Transfer outside the EEA
If a transfer of the Project Content takes place to a country outside the European Economic Area, Blackbear ensures a valid transfer mechanism within the meaning of Chapter V GDPR. The sub-processors and their processing location are listed in Annex 2.
Article 7. Assistance
Taking into account the nature of the processing, Blackbear provides the Client with reasonable assistance in responding to data subject requests and in its obligations regarding security, personal data breaches and a data protection impact assessment. Blackbear informs the Client without undue delay of a personal data breach affecting the Project Content. Blackbear forwards to the Client a data subject request concerning the Project Content.
Article 8. Return or deletion
After the end of the processing, Blackbear deletes the Project Content, or returns it to the Client at the Client’s request, at the Client’s choice, unless a statutory obligation requires Blackbear to retain it.
Article 9. Audits
Blackbear makes available to the Client the information necessary to demonstrate compliance with the obligations under Article 28 GDPR, and enables and cooperates with audits carried out by or on behalf of the Client.
Blackbear’s liability under this Data Processing Agreement falls under the liability regime in the Terms and Conditions for Clients.
This Data Processing Agreement is drawn up in Dutch. In the event of a difference between the Dutch and the English text, the Dutch text prevails.
Annex 1. Description of the processing
Nature and purpose: storing, organising and making available the Project Content to the other Party to the Project, and, to the extent that the Client uses the AI-supported scoping, analysing the input supplied for the purpose of a draft SOW, all in order to provide the Platform Services.
Duration: for as long as the Client has access to the Platform, plus the period for return or deletion.
Categories of data subjects: the natural persons whose personal data the Client submits in an Initiative, SOW or Project, and Contractors to the extent that their contributions to the Project constitute Project Content.
Types of personal data: name and contact details, position and organisation details, and other personal data that the Client includes in documents, Deliverables, messages and attachments. Special categories of personal data are not processed.
Annex 2. Sub-processors
This annex was last updated on 1 August 2026.
Amazon Web Services
Service: hosting and storage of uploaded files, Deliverables and backups
Processing location: European Union (Paris region)
Transfer mechanism: not applicable, within the EEA
OpenAI
Service: AI-supported scoping of the input supplied
Processing location: United States
Transfer mechanism: EU-US Data Privacy Framework and standard contractual clauses; zero retention configured
PandaDoc
Service: generation and electronic signing of the Underlying Project and the SOW
Processing location: United States
Transfer mechanism: EU-US Data Privacy Framework and standard contractual clauses
Blackbear has concluded a data processing agreement with each sub-processor. Service providers that process only platform data, for which Blackbear is itself the controller, are described in the Privacy Policy and are not sub-processors within the meaning of this Data Processing Agreement.
Annex 3. Security measures
Blackbear takes at least the following measures: role-based access management with multi-factor authentication for administrator access; encryption of personal data in transit and at rest; logical separation of the data of different Clients; regular, encrypted backups that are stored within the European Union; logging and monitoring; protection of network and application against unauthorised access; periodic review and maintenance of security; contractual confidentiality by staff and engaged third parties; and a procedure for detecting, handling and reporting security incidents and personal data breaches.