Version 1.3, last updated 8 September 2026.
This Data Processing Agreement (DPA) forms an integral part of the Collectmaxx Terms & Conditions and governs how Collectmaxx B.V. processes personal data on behalf of its customers, in accordance with the GDPR.
This Data Processing Agreement(the "DPA") is entered into between the Customer and Collectmaxx B.V. It forms an integral part of the Collectmaxx Terms & Conditions (the"Agreement") and is accepted by the Customer together with thoseTerms & Conditions when creating an account. No separate signature isrequired.
This agreement on thecollection, storage and use of documents and information has been entered intoby and between:
the legal entity that creates anaccount and accepts the Collectmaxx Terms & Conditions, identified by thecompany details provided in its account (hereinafter the "DataController" or "Controller"),
and
Collectmaxx B.V.,Scheepmakerspassage 183, 3011 VH Rotterdam, The Netherlands, companyregistration number 95712526 (hereinafter the "Data Processor" or"Processor").
The parties above arehereinafter individually referred to as "Party" and together as"Parties".
2.1 By accepting the CollectmaxxTerms & Conditions during sign-up, the Parties agree to enter into thisData Processing Agreement, including the following Schedules that form anintegral part hereof:
• Schedule 1: General Specifications
• Schedule 2: Specification of the Processing
• Schedule 3: Security Measures
• Schedule 4: Sub-processors (of the Processor)
3.1 The definitions as includedin Article 4 of the GDPR are applicable in this DPA. These definitions arewritten with capital letters in this DPA.
3.2 The following additionaldefinitions are applicable in this Data Processing Agreement:
• Agreement: the agreement executed between theController and the Processor under which the Processor processes Personal Datafor the Controller for the purpose of the performance of that agreement; theAgreement is defined in Schedule 1.
• Applicable Legislation and Regulations on theProcessing of Personal Data: the applicable legislation and regulations on theProcessing of Personal Data, including future amendments and/or supplementsthereto, including but not limited to the GDPR.
• Personal Data: data which can be used either directlyor indirectly to identify a natural person, in the sense intended in the GDPR.
• DPA: this Data Processing Agreement, including allattachments thereto referred to as Schedules.
• Employee: an employee or other person engaged by theProcessor who is authorized to process the Personal Data under the directauthority of the Processor.
• GDPR: Regulation (EU) 2016/679 of the EuropeanParliament and of the Council of 27 April 2016 on the protection of naturalpersons regarding the processing of personal data and on the free movement ofsuch data and repealing Directive 95/46/EC (General Data ProtectionRegulation).
• Sub-processor: a third party, including but not limitedto subsidiaries, other affiliates, and third-party suppliers of the Processor,engaged by the Processor to carry out specific processing activities on behalfof the Controller.
4.1 This Data ProcessingAgreement concerns the Parties' obligations regarding the processing ofPersonal Data.
4.2 This DPA replaces any previous agreements between the Parties on the processing of the Personal Data. However, if the Parties have entered into a separately signed data processing agreement, that signed agreement prevails and this DPA does not apply. This Data Processing Agreement can only be amended in writing.
4.3 In the event of any conflictbetween the provisions of this DPA and the Agreement, the provisions of thisDPA shall prevail.
4.4 This Data ProcessingAgreement shall apply to all current and future deliveries by the Processorunder the Agreement and to all companies within the Data Controller's group ofcompanies for whom the Processor processes Personal Data. This agreement shallalso apply to all companies within the Data Processor's group which processdata for the Data Processor.
5.1 The Processor shall processPersonal Data on behalf of the Data Controller. The Data Controller hasspecified its instructions regarding the processing of the Personal Data.
5.2 The Data Controllerinstructs the Processor to process the Personal Data to provide its servicesunder the Agreement.
5.3 The Processor shallexclusively process the Personal Data on documented instructions from the DataController.
5.4 Article 5.3 is notapplicable in so far as applicable Union law or provisions of Member State lawto which the Processor is subject require the Processor to process the PersonalData in any other way. In such a case, the Processor shall notify the DataController of this legal requirement in writing prior to the processing, unlessthat law prohibits such information on important grounds of public interest.
5.5 The Processor shallexclusively process the Personal Data to the extent that the processing isnecessary for the purpose of the performance of the Agreement, and never forits own use, for the benefit of third parties and/or other purposes.
5.6 The Processor shall onlyprocess the Personal Data in accordance with the specifications in Schedule 2.This Schedule specifies amongst other things: (a) the nature and purpose of theprocessing; (b) the categories of Data Subjects to which the Personal Datapertain; (c) the Personal Data that are processed; and (d) the retention periodof the Personal Data.
5.7 The Processor is not allowedto transfer, access, process or otherwise make available Personal Data incountries outside the EU/EEA or to a country or territory that has not receivedan adequacy decision from the European Commission, except for pre-approvedSub-processors listed in Schedule 4 and under the conditions set forward inArticle 5.8 of this DPA.
5.8 The Processor can transfer,access, process or otherwise make Personal Data available to pre-approvedSub-processors listed in Schedule 4, provided that a valid transfer mechanismunder Chapter V of the GDPR is in place for any Sub-processor located outsidethe EU/EEA.
5.9 In the event a change in theperformance of the Agreement requires a change in this DPA, the Parties shallnegotiate in good faith on a change of this DPA. A Sub-processor shall not beallowed to implement a change in the performance of the Agreement that requiresa change of this DPA without the Processor's prior written approval.
6.1 The Processor shall ensurethat its Employees have committed themselves to confidentiality of the PersonalData or are under an appropriate statutory obligation of confidentiality of thePersonal Data. Upon written request of the Controller, the Processor shallprovide the Data Controller with evidence of compliance with this obligation.
7.1 The Processor shallimplement appropriate technical and organisational measures to ensure anappropriate level of security of the Personal Data. To this end, the Processorhas at least implemented the technical and organisational measures as describedin Schedule 3.
7.2 The appropriate level ofsecurity of the Personal Data as referred to in Article 7.1 is determinedconsidering the state of the art, the costs of implementation and the nature,scope, context and purposes of processing, as well as the risk of varyinglikelihood and severity for the rights and freedoms of natural persons. Inassessing the appropriate level of security of the Personal Data, the Processorshall consider the risks that are presented by the processing, from accidentalor unlawful destruction, loss, alteration, unauthorised disclosure of, oraccess to Personal Data transmitted, stored or otherwise processed.
7.3 Upon written request of theData Controller, the Processor shall inform the Data Controller of thetechnical and organisational measures implemented by the Processor to ensure anappropriate level of security of the Personal Data.
7.4 The Processor shall ensurethat any Employee who has access to the Personal Data shall only process thePersonal Data in accordance with the Data Controller's instructions as referredto in Article 5.2, unless such person is required to process the Personal Dataotherwise by Union or Member State law.
8.1 The Processor is authorisedto engage other Sub-processors for the purpose of processing the Personal Data.A list of Sub-processors to which the Processor has subcontracted (part of) theprocessing of Personal Data is included in Schedule 4.
8.2 The Processor can appointnew Sub-processors for the processing of the Personal Data. The Processor willnotify the Controller of the addition or replacement of any Sub-processor atleast 60 days before such change, by updating the Sub-processor list on thispage and notifying the Controller by email at the address registered to theController's account.
8.3 The Processor shall give theData Controller the opportunity to object to such changes. In the event of anobjection by the Data Controller to an intended addition or replacement of aSub-processor, where the addition or replacement of the Sub-processor would notresult in a breach by the Processor of this DPA or Applicable Legislation andRegulations on the Processing of Personal Data, the Processor shall have theright to terminate the Agreement upon reasonable notice, without the DataController having any right to claim any damages as a result of suchtermination.
8.4 The Processor shall ensureby means of written agreements that all its subcontractors and Sub-processorsprocessing the Personal Data listed in Schedule 2 are bound by data protectionobligations compatible with those of the Processor under this Data ProcessingAgreement. Upon written request of the Data Controller, the Processor shallprovide the Data Controller with evidence of the Sub-processor's compliancewith this obligation.
8.5 The Processor shall remainfully liable to the Data Controller for its subcontractors' and Sub-processors'failure to fulfil their data protection obligations.
9.1 Considering the nature ofthe processing, the Processor shall assist the Data Controller by appropriatetechnical and organisational measures, insofar as this is possible, for thefulfilment of the Data Controller's obligation to respond to requests forexercising the Data Subject's rights laid down in Chapter III of the GDPR.
9.2 The Processor shallimmediately inform the Data Controller of a request of a Data Subject addresseddirectly to the Processor.
9.3 In the event the Controllercarries out a data protection impact assessment as referred to in Article 35 ofthe GDPR on the processing of the Personal Data, the Processor shall uponwritten request of the Controller assist the Controller by providing theinformation available to the Processor and related to the processing of thePersonal Data by the Processor, necessary for the Controller to comply with theminimum requirements of the assessment as described in Article 35(7) of theGDPR and/or for any possible prior consultation of the Supervisory Authority asreferred to in Article 36 of the GDPR.
10.1 The Processor shall notifythe Data Controller of a Personal Data Breach without undue delay after havingbecome aware of it, where feasible within 24 hours of discovery, in accordancewith the notification procedure described in Schedule 1. Where and to theextent that it is not possible to provide the required information at the sametime, the information may be provided in phases without undue further delay.
10.2 The Processor is alsoresponsible for providing notifications about data breaches occurring at itsSub-processors or subcontractors that can affect the Personal Data, under thesame conditions referred to in Article 10.1.
10.3 The Processor shalldocument any Personal Data Breaches relating to the Personal Data in aregister, comprising the facts relating to the Personal Data Breaches (inaccordance with the details described in Schedule 1), their effects and theremedial actions taken. Upon written request of the Data Controller, theProcessor shall provide the Data Controller with a redacted copy of thisregister that only discloses the records relevant to the Data Controller.
11.1 The Data Controller has theright to have an audit performed in respect of the Processor's organisation bya (legal) person authorised by the Data Controller, to demonstrate that theprocessing of the Personal Data by the Processor complies with the provisionsof this DPA, the Agreement and Applicable Legislation and Regulations on theProcessing of Personal Data. The costs of the audit are at the DataController's expense.
11.2 The Data Controller shallgive reasonable notice to the Processor of the intention to perform an audit.Reasonable notice shall be considered at least 60 days prior to commencing anyaudit action.
11.3 The audit provision doesnot prejudice the Data Controller's other rights, including any possible rightto damages.
12.1 The Processor is liable forthe Data Controller's damages resulting from a breach of this DPA by theProcessor itself or by the Processor's Sub-processors or subcontractors.
12.2 The aggregate liability ofthe Processor under this DPA and the Agreement combined is equal to the maximumliability of the Processor under the Agreement.
12.3 Any limitation of liabilityof the Processor due to a breach of this DPA is not applicable in case ofintent or gross negligence of the Processor.
12.4 Any damages for which theController shall be liable under Article 82(2) GDPR shall be deducted from theliability of the Processor under this Article 12.
13.1 This Data ProcessingAgreement is entered into for an indefinite term, starting on the effectivedate as defined in Schedule 1.
13.2 This Data ProcessingAgreement ends when all Personal Data processed by the Processor have beenreturned to the Data Controller and any copy of it has either been destroyed orprocessed in accordance with the Data Controller's instructions by the Processoras well as any of its Sub-processors or subcontractors involved in furtherprocessing the Personal Data.
13.3 This Data ProcessingAgreement cannot be terminated by one of the Parties separately from theAgreement.
13.4 Termination or expirationof this Data Processing Agreement shall not discharge the Processor from itsconfidentiality obligations pursuant to Article 6.
14.1 This Data ProcessingAgreement is governed by the laws of the Netherlands.
14.2 All disputes arisingbetween the Parties resulting from this DPA shall be exclusively submitted tothe competent court in Rotterdam.
Agreement. The agreementunder which the Processor processes the Personal Data is the Collectmaxx Terms& Conditions, as accepted by the Data Controller when creating its account.
Effective date. Theeffective date of this Data Processing Agreement is the date on which the DataController accepts the Collectmaxx Terms & Conditions.
Personal Data Breaches. TheProcessor shall report all Personal Data Breaches to the email addressregistered to the Data Controller's account. In addition to Article 10, theProcessor shall provide the Controller with the following information for everyPersonal Data Breach:
• a summary of the incident in which the Personal DataBreach occurred;
• the timing of the breach (date or period);
• the number of Data Subjects involved in the breach, orat least an estimate of the minimum and maximum in case the exact number is notfully known;
• the categories of Data Subjects involved in the breach;
• the nature of the breach (reading (confidentiality),copying, changing (integrity), removing or destroying (availability), theft, orother (including specification));
• the types of Personal Data involved in the breach (nameand address details, telephone numbers, email addresses or other addresses forelectronic communication, access or identification information, financialinformation, tax or social security numbers, copies of identificationdocuments, gender, date of birth and/or age, special categories of PersonalData, or other (including specification));
• the possible consequences of the breach for the privacyof the Data Subjects (stigmatisation or exclusion, damage to health, exposureto (identity) fraud, exposure to spam or phishing, or other (includingspecification)).
Contact details of the Processor's DPO. The Processor's DPO can be reached via marketing@alphacomm.nl or in writing at Scheepmakerspassage 183, 3011 VH Rotterdam, The Netherlands.
Contact details of the DataController's DPO. The contact details provided in the Data Controller'saccount apply. The Data Controller can register a dedicated DPO contact in itsaccount settings.
Nature and purpose of theprocessing. Providing reminder services for the clients of the DataController as well as debt collection services for the Data Controller.
Data Subject category: endcustomers of the Data Controller, processed by the Processor on behalf ofthe Data Controller.
• Contact details (first and last name, address, zipcode, email, phone number). Retention period: 3 months. Purpose: communicationand sending reminders.
• Payment details. Retention period: 2 years. Purpose:evidence of payment.
Data Subject category:employees of the Data Controller.
• Last name, first name, work phone number, emailaddress(es). Retention period: until the employee leaves the Data Controller'scompany or the end of the Agreement or DPA. Purpose: performance of theAgreement and of this DPA and maintaining the B2B relationship between theParties, including technical and commercial communications.
Personnel. Employees ofthe Processor have defined and documented security roles and responsibilities,addressed prior to employment. During employment, employees are periodicallymade aware of rules and procedures concerning security and regulatoryrequirements. All employees agree to and sign the Alphacomm IT SecurityPolicies document, covering information classification, information security,network security, acceptable use, protection of stored data, physical security,protection of data in transit, disposal of stored data, security awareness,security incident response, transfer of sensitive information, user accessmanagement and access control. Background verification checks are carried outon all new employees prior to employment.
Password protection andmulti-factor authentication. All workstations and networks are secured withpassword protection. Passwords must meet strength requirements (length andcomposition, exceeding 12 characters), differ from the last ten passwords used,be changed every 90 days or less, not be visible when entered, be stored inencrypted format and be changed directly when initially provided. Networkaccess is restricted to registered workstations and devices; remote access isonly possible via strong authentication mechanisms, and all access and login attemptsare logged and monitored. User access and rights are limited through usermanagement, accessible only to certain roles. User credentials are neverdisclosed over insecure channels. Access to platform hosting and data storageis restricted to registered users with multi-factor authentication from aregistered device. Password resets are only possible via at least two-factorauthentication.
Data transfers. All datatransfers in and out of the platform are carried out using known secure andauthenticated protocols (SFTP).
Vulnerability scanning andpatching. All assets that are part of or connected to the infrastructureused for delivering a service are scanned on a regular basis by differentsecurity scans. Penetration tests are possible on request. Identifiedvulnerabilities are prioritized depending on their assigned score and risk andtreated accordingly. Critical vulnerabilities that pose an immediate threat toconfidentiality, integrity or availability are treated without undue delay.
Media cleaning. All mediacarrying information are completely and irrecoverably cleaned or destroyedbefore re-use or disposal.
Network segmentation andsecurity zoning. Network segments support a layered security model, withnetwork filters between segments through which only authorized traffic canpass. Network documentation describes the network design and IP number plan.Networks are monitored for capacity, availability and malicious activities, andevents are handled appropriately.
Traffic data. Trafficdata is irreversibly anonymized or deleted when it is no longer necessary forthe transfer of communication, except for billing purposes, legal dataretention (6 months for telephony data, 3 months for internet data) or marketanalysis and after-care activities using anonymized data only.
Encryption. Personal Datais encrypted both in transit and at rest using strong encryption algorithms.
Hosting. The Collectmaxxplatform is hosted on Amazon Web Services (AWS) in Germany (Frankfurt region).Data is encrypted and stored on different nodes in a highly redundant datacluster, which minimizes the chance of data loss.
Privileged accounts andchange management. Privileges assigned to accounts or groups which have thepower to damage the infrastructure directly are protected by a four-eyesprinciple (at least two people present during activities, auditable), centrallogging of the workstations from which activities are conducted, privacy bydesign and by default, a separate staging environment, roll-back scenarios forall releases, automated and manual testing of all changes before and afterdeployment to production (functionality and known security issues), and restrictionof these activities to the Processor's own network.
Monitoring. Allplatforms, hosting services and networks are monitored for computing power,capacity, anomalies, performance and active connections, with notifications indefined scenarios. An encrypted audit log is kept of all activities.
• Amazon Web Services EMEA SARL, 5 Rue Plaetis, 2338Luxembourg, Luxembourg. Processor platform for all services; hosting in Germany(Frankfurt region).
• MessageBird B.V., Baarsjesweg 285 H, 1058 AE Amsterdam,The Netherlands. Communication services.
• Sound of Data B.V., Waalhaven O.z. 83 L, 3087 BMRotterdam, The Netherlands. Contact center solutions.
• Spottler Group (Flowmailer), Wilhelminakade 308, 3072AR Rotterdam, The Netherlands. Email service API.
• ReadSpeaker, Princenhof Park 13, 3972 NGDriebergen-Rijsenburg, The Netherlands. Text-to-speech service.
• ElevenLabs, 169 Madison Ave #2484, New York, NY 10016,United States of America. Text-to-speech and agentic AI voice service.Transfers to ElevenLabs take place on the basis of a valid transfer mechanismunder Chapter V of the GDPR.