Data processing agreement
Last updated: 10 August 2026
If you enter personal data of your own customers, staff or other data subjects into Munitor Compliance, your organisation is the controller and Munitor is the processor within the meaning of article 28 GDPR. This page summarises the core terms; request the signed data processing agreement itself via contact@munitor.nl. This summary is not legal advice and does not replace the signed agreement.
Parties and roles
Your organisation is the controller; Munitor is the processor within the meaning of article 28 GDPR. Munitor processes personal data solely to deliver the service and never for its own purposes such as third-party marketing.
Subject and duration
Munitor processes personal data solely on the instructions of your organisation, for the duration of your subscription and according to your written instructions as recorded in this agreement and the service itself.
Categories of data subjects and data
Think of names, roles and contact details of staff you record as the owner of a measure, and of data in evidence documents you upload. You, as controller, determine exactly which data that is.
Sub-processors
Munitor engages sub-processors for hosting (within the EU), payments (Stripe) and AI functionality (Anthropic, PBC). Every sub-processor that processes personal data is itself bound by its own data processing agreement with Munitor. An up-to-date list is available via contact@munitor.nl; we inform you in advance of material changes to that list.
Security measures
EU hosting, encryption of traffic and passwords, role-based access within your workspace, an audit log that records changes to measures and evidence so you can check who changed what, and a mime allowlist with a maximum file size of 25 MB per uploaded evidence document.
Data breach notification
If we discover a security incident involving personal data you entered, we notify you without undue delay, so you can assess yourself whether a report to the Autoriteit Persoonsgegevens is required.
Rights of data subjects
If Munitor receives a request from a data subject about data you, as controller, had processed (access, correction, deletion, objection), we forward it to you and cooperate with handling it; you remain responsible for the substantive assessment and the response to the data subject.
Transfers outside the EEA
Where a sub-processor processes data outside the European Economic Area, this happens on the basis of the EU Standard Contractual Clauses (SCCs) or a comparable recognised transfer mechanism.
Return and deletion at the end of the agreement
At the end of your subscription you receive your data and documentation via the exportable evidence dossier; Munitor then deletes the personal data from its systems within a reasonable period, unless a statutory retention obligation requires longer storage. The exact retention period after termination is recorded in the signed agreement.