Juridisch
Verwerkersovereenkomst
Hoe we persoonsgegevens namens jou verwerken, en waar we ons als verwerker aan binden.
Dit document is alleen in het Engels beschikbaar. Dat is bewust: dat is de gezaghebbende versie, en een vertaalde juridische tekst zou een tweede formulering zijn die niemand heeft gecontroleerd.
Laatst bijgewerkt 20 aug 2026
This Data Processing Agreement ("DPA") forms part of the Provibr Terms of Service and applies automatically to every Customer. No signature is needed: by using the Service you and we are bound by it. It exists because the infrastructure data you manage through Provibr can contain personal data of your own customers, and Article 28 GDPR requires the arrangement between us to be in writing.
1Parties, applicability, and precedence
- This DPA is entered into between the Customer (as defined in the Terms of Service — the business on whose behalf an account is created) and FullStack Studio, registered in the Netherlands (Chamber of Commerce no. 42097493), reachable at info@provibr.com.
- It applies to all processing of personal data that FullStack Studio performs on behalf of the Customer in providing the Service, for as long as the agreement under the Terms of Service runs.
- Where this DPA and the Terms of Service conflict on the subject of processing personal data, this DPA prevails. On everything else, the Terms of Service prevail.
2Roles and scope — what this DPA covers, and what it does not
- For the data described in Annex 1 — the infrastructure data the Customer manages through the Service, insofar as it contains personal data — the Customer is the controller and FullStack Studio is the processor.
- Outside the scope of this DPA: personal data for which FullStack Studio is itself the controller — the Customer's account and login data, billing and payment records, support tickets insofar as they concern the relationship between the Customer and FullStack Studio, and the audit log of the platform. That processing is described in the Privacy Statement. This is also why our payment provider (Stripe), our invoicing provider (Moneybird), the AI provider behind the chat assistant on our website (Anthropic), and the profile-picture service in the panel (Gravatar) are not sub-processors under this DPA: they process data under our own controller responsibility.
- The Customer warrants that it has a lawful basis for the personal data it brings into the Service, and that it is entitled to engage FullStack Studio as processor for it.
3Instructions
- FullStack Studio processes the personal data in Annex 1 only on the Customer's documented instructions. The Customer's documented instructions are: use of the Service as it is designed — the commands issued through the panel and the API, the configuration set in the account, and the operation of the agent that follows from them.
- Additional or deviating instructions are only binding once agreed in writing, and FullStack Studio may charge reasonable costs for carrying them out.
- If FullStack Studio believes an instruction violates the GDPR or other applicable data protection law, it will inform the Customer and may suspend carrying it out until the instruction is confirmed or changed.
- FullStack Studio may process the data where required by EU or Member State law; in that case it informs the Customer of that legal requirement before processing, unless the law prohibits this.
4Confidentiality
FullStack Studio ensures that every person authorised to process the personal data — employees and contractors alike — is bound by a contractual or statutory duty of confidentiality, and that access follows least privilege: no one has access who does not need it to provide the Service.
5Security
- FullStack Studio implements and maintains the technical and organisational measures described in Annex 3, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as required by Article 32 GDPR.
- FullStack Studio may update the measures in Annex 3 over time, provided the overall level of protection does not decrease.
- The Customer remains responsible for the security of everything on its own side: its infrastructure, the credentials it supplies, the accounts and permissions it configures, and the devices its members use.
6Sub-processors
- The Customer gives general written authorisation for the sub-processors listed in Annex 2.
- FullStack Studio may add or replace sub-processors. Changes are announced in the panel and/or by email before the new sub-processor starts processing personal data.
- If the Customer has reasonable data-protection grounds to object to a change, it must raise the objection within fourteen days of the announcement. The parties will then confer; if no solution is found, the Customer may end the agreement effective at the end of its current billing period, as its sole remedy.
- FullStack Studio imposes on every sub-processor data-protection obligations that offer at least the level of protection of this DPA, and remains fully liable towards the Customer for the sub-processor's performance, within the limits of section 12.
7Assistance with data subject rights
- If a data subject (for example, one of the Customer's end customers) contacts FullStack Studio directly about data processed under this DPA, FullStack Studio does not respond substantively but refers the request to the Customer without undue delay.
- Taking into account the nature of the processing, FullStack Studio assists the Customer with appropriate technical and organisational measures, insofar as reasonably possible, in fulfilling data subject requests (access, rectification, erasure, restriction, portability, objection). In practice the panel itself is the primary tool: the Customer can view, correct, and remove its own records directly.
- For assistance that goes beyond what the Service already provides, FullStack Studio may charge reasonable costs.
8Personal data breaches
- FullStack Studio notifies the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA.
- The notification contains what is known at that moment — the nature of the breach, the categories and approximate number of data subjects and records concerned insofar as they can be determined, the likely consequences, and the measures taken or proposed — and is supplemented as more becomes known. FullStack Studio need not delay an initial notification until all facts are established.
- The Customer is responsible for its own notifications to supervisory authorities and to data subjects. FullStack Studio's notification to the Customer is not an acknowledgement of fault or liability.
9Assistance with DPIAs
Taking into account the nature of the processing and the information available to it, FullStack Studio provides reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, insofar as they concern the processing under this DPA. The Privacy Statement, this DPA, and Annex 3 are the first source; assistance beyond that may be charged at reasonable costs.
10Audits
- FullStack Studio makes available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits.
- Audits follow this order: first, written questions and existing documentation (this DPA, Annex 3, the Privacy Statement, and any certifications or third-party reports that exist at that time). Only where that is demonstrably insufficient may the Customer conduct, at most once per twelve months, an audit by an independent auditor bound to confidentiality.
- An audit requires thirty days' written notice, takes place during business hours, must not disrupt the Service, and never extends to data of other customers or to systems that would expose it. The Customer bears the costs of the audit, including FullStack Studio's reasonable internal costs.
11International transfers
All platform data is stored on FullStack Studio's own servers in the Netherlands. FullStack Studio does not transfer personal data under this DPA outside the European Economic Area, with one exception: traffic to the website and panel transits Cloudflare (see Annex 2), covered by the EU–US Data Privacy Framework and/or Standard Contractual Clauses. The agent's connection to the platform does not pass through Cloudflare.
12Term, deletion, and liability
- This DPA runs as long as the agreement under the Terms of Service runs, and ends with it.
- After the end of the agreement, FullStack Studio deletes the personal data processed under this DPA in accordance with the retention periods in the Privacy Statement, unless EU or Member State law requires storage. Exporting data the Customer wants to keep is the Customer's responsibility, before the agreement ends — the panel provides its records while the agreement runs.
- The liability provisions of the Terms of Service (section 12 of the Terms, including the cap and the exclusions) apply to this DPA in full. This DPA creates no separate or additional liability regime.
- This DPA is governed by Dutch law, with the same venue as the Terms of Service.
Annex 1 — Description of the processing (Article 28(3) GDPR)
| Element | Description |
|---|---|
| Subject matter | Managing the Customer's own IT infrastructure (hypervisors, hosting panels, game panels, dedicated machines, network equipment) through the Provibr panel, the public REST API, and the agent. |
| Duration | The term of the agreement under the Terms of Service. |
| Nature of the processing | Storage, display, transmission, and structured logging of infrastructure records; relaying of commands and console sessions; collection of usage metrics. |
| Purpose | Providing the Service: inventory, provisioning, monitoring, address management, automation, and auditability of the Customer's infrastructure. |
| Categories of data subjects | The Customer's end customers and their users; the Customer's own staff, insofar as they appear in the records the Customer manages. |
| Types of personal data | Data that can identify individuals insofar as the Customer puts it into its records: server and machine hostnames; IP and MAC addresses; IPAM records, reservations, and free-text notes; server inventory and configuration; usage metrics tied to servers; structured, redacted agent log records; script and template content written by the Customer; console session metadata (who, when, duration, byte counts — never session content); names and email addresses the Customer enters (for example a game panel account owner). |
| Special categories of data | None intended. The Service is not designed for special-category data, and the Customer must not direct such data into it. |
Annex 2 — Sub-processors
| Sub-processor | Establishment | Processing | Location of processing |
|---|---|---|---|
| Cloudflare, Inc. | United States | CDN and security proxy: website and panel traffic in transit (requested URLs, IP addresses of panel users) | Global edge network; transfers covered by the EU–US Data Privacy Framework and/or SCCs |
Notes:
- Hosting is not sub-processed. The platform runs on FullStack Studio's own servers in the Netherlands.
- The agent's traffic does not pass through Cloudflare: agents connect directly to the platform gateway over mutually authenticated TLS.
- Stripe (payments) and Moneybird (invoicing) process personal data under FullStack Studio's own controller responsibility and are therefore not sub-processors under this DPA; they are described in the Privacy Statement.
Annex 3 — Technical and organisational measures
Transport and authentication
- All traffic between browser, platform, and agent is encrypted in transit on every leg of the route, including between the CDN and the platform's own servers (TLS 1.2 or newer).
- Agents authenticate with mutual TLS using per-agent certificates, with certificate pinning on the platform side; agent certificates rotate automatically and can be revoked, after which the agent wipes its local identity and credential vault.
- The agent connects outbound only; the Customer opens no inbound ports.
Data separation and access control
- Strict tenant isolation: every query, realtime channel, and event is scoped to a single organisation; realtime connections are authorised with single-use, organisation-bound tickets.
- Role- and permission-based access within an account (modules, per-server assignment, capabilities); members see only what their permissions allow.
- Access to the public REST API uses per-member keys with explicit scopes: a request is allowed only where both the key's scope and the key holder's own permissions allow it, so a key can never do more than the person who created it. Keys are stored as a hash and shown once, can carry an expiry date and an IP allowlist, stop working the moment the membership ends or the key is revoked, and are rate-limited per key and per account; failed authentication attempts are logged and throttled.
- Provibr support staff can access an account only by temporarily acting as one of its members, inheriting exactly that member's permissions and no more; every such session is recorded in an immutable audit trail and shown to the Customer in its own activity log. Actions that could cause lasting harm — deleting or reinstalling a resource, changing stored credentials — stay blocked until a member of the account generates a one-time consent code and hands it over, and the Customer can revoke that access at any time. Support staff can never view or set a member's password or read its two-factor recovery codes.
- Panel accounts support two-factor authentication and passkeys.
Handling of secrets
- Credentials for the Customer's infrastructure are stored encrypted on the Customer's own agent host, with a key bound to that machine; they pass through the platform once, transiently, and audit records keep field names only, never values.
- Secrets stored on the platform (payment provider keys, script secrets) are encrypted at rest with AES-256-GCM.
- Console sessions are relayed as an encrypted byte stream; only session metadata is recorded, never content.
- Agent log records are structured (fixed event codes with parameters) and known secret patterns are redacted before records leave the Customer's host.
Continuity and accountability
- Daily database backups with fourteen-day rotation, stored on the same infrastructure in the Netherlands.
- An append-only audit log records actions performed in the panel, including who performed them.
- Software updates to the agent are cryptographically signed and verified before installation.
Organisational
- Access to production systems follows least privilege and is limited to persons who need it to provide the Service.
- Persons authorised to process personal data are bound by confidentiality (section 4).
Begin met één host en één agent
Maak een account aan, installeer de agent met één commando en koppel je eerste Proxmox-host. De proefperiode loopt 14 dagen en vraagt geen betaalgegevens.