Custilo
Coming soon

Data processing agreement

Businesses using Custilo are the controllers of their customers' data, and Custilo processes it on their behalf. This agreement sets out how, as required by article 28 of the GDPR.

Version 2026-10-03, last updated 3 October 2026. Permanent link to this version

Draft

This text is a draft that is being reviewed and may still change. Values in square brackets are still to be completed. Questions: hello@custilo.com.

1. Parties and scope

This data processing agreement (“DPA”) is concluded between the business that uses Custilo (the “Customer”, controller) and [Legal company name], [Legal form, e.g. BV/SRL], enterprise number [KBO/BCE enterprise number], registered office at [Registered office address, Belgium] (“Custilo”, processor). It forms part of the terms of service (the “Terms”) and is accepted together with them. It applies to all personal data that Custilo processes on behalf of the Customer when providing the Service (“Customer Personal Data”). Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meaning given in the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”).

Annex 1 describes the processing, Annex 2 the security measures, and the sub-processors page forms Annex 3.

2. Instructions

  • Custilo processes Customer Personal Data only on the documented instructions of the Customer, including for transfers to a third country, unless Union or Member State law requires otherwise; in that case Custilo informs the Customer of that legal requirement before processing, unless that law prohibits it.
  • The Agreement, this DPA and the Customer’s configuration and use of the Service (for example importing customers, setting up campaigns, choosing alert recipients, exporting or deleting data) are the Customer’s complete documented instructions. Other instructions must be agreed in writing.
  • These instructions include that Custilo: asks each alert recipient who is not a member of the workspace to confirm before sending them alerts, and keeps a record of people who stopped alerts so they are not added again; keeps, after the Customer erases a customer who unsubscribed, bounced, complained or was suppressed, a hash of the address with that status, so that the opt out keeps being respected; and, where address validation is used, keeps the validation result with the address for the Customer only, so the address is not checked twice (see section 10).
  • Custilo informs the Customer immediately if, in its opinion, an instruction infringes the GDPR or other data protection law.

3. Obligations of the Customer

The Customer is responsible for the lawfulness of the processing it instructs: it has a legal basis for collecting the data and for contacting its customers for feedback, it informs the data subjects as required by articles 13 and 14 of the GDPR (including that it uses a processor to send feedback requests), and it only provides the data needed for that purpose. The Customer does not provide special categories of personal data (article 9 GDPR) or data about criminal convictions unless it has checked that this is lawful and necessary.

4. Confidentiality

Custilo ensures that the persons it authorises to process Customer Personal Data are bound by confidentiality, by contract or by law, and only access the data as far as needed to provide, support or secure the Service.

5. Security

Custilo implements the technical and organisational measures required by article 32 of the GDPR, described in Annex 2. It may update these measures, as long as the overall level of protection is not reduced.

6. Sub-processors

  • The Customer gives Custilo a general authorisation to engage sub-processors. The current sub-processors are listed on the sub-processors page (Annex 3).
  • Custilo informs the Customer by email at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable grounds relating to data protection within that period. The parties then discuss the objection in good faith. If no solution is found, the Customer may terminate the affected subscription before the change takes effect, and receives a refund of fees paid in advance for the period after termination.
  • Custilo imposes on each sub-processor, by contract, data protection obligations that offer at least the same level of protection as this DPA, in particular sufficient guarantees of appropriate technical and organisational measures. Custilo remains fully liable to the Customer for the performance of its sub-processors’ obligations.

7. Transfers outside the European Economic Area

Customer Personal Data is stored in a database hosted in the European Union. The Customer authorises transfers to the sub-processors listed in Annex 3, in the locations listed there. Where a sub-processor processes data in a country outside the European Economic Area that does not benefit from an adequacy decision, Custilo concludes with it Module 3 (processor to processor) of the Standard Contractual Clauses adopted by the European Commission (Commission Implementing Decision (EU) 2021/914) and documents a transfer impact assessment, with supplementary measures where needed. For providers certified under the EU-U.S. Data Privacy Framework, Custilo may rely on the corresponding adequacy decision, and also concludes the Standard Contractual Clauses as a fallback.

8. Assistance to the Customer

  • Data subject requests: the Service lets the Customer find, export, correct and delete its customers’ data, and every survey email has an unsubscribe link. If Custilo receives a request from a data subject directly, it forwards it to the Customer without undue delay and does not answer it itself, unless the Customer instructs it to. Custilo otherwise assists the Customer, by appropriate technical and organisational measures, in answering such requests.
  • Other obligations: taking into account the nature of the processing and the information available to it, Custilo assists the Customer in meeting its obligations under articles 32 to 36 of the GDPR (security, breach notification, data protection impact assessments and prior consultation).

9. Personal data breaches

Custilo notifies the Customer without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification describes, as far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information not available at first is provided as soon as possible. Custilo takes the measures needed to contain the breach and limit its consequences. Notifying the supervisory authority and the data subjects is the Customer’s responsibility, with Custilo’s assistance.

10. Deletion and return of data

The Customer can export its data at any time during the Agreement. When an owner deletes a workspace, it is locked and all Customer Personal Data in it is permanently deleted 30 days later (the grace period allows the Customer to restore it or export it). When the Agreement ends for another reason, Custilo deletes the workspace in the same way on the Customer’s request, and in any case within [90] days after the end of the Agreement. Copies in backups maintained by our hosting provider are overwritten within [7] days. Custilo only keeps data longer where Union or Member State law requires it. Two records are kept on the Customer’s instructions (section 2): the hash of an opted out address, for the lifetime of the workspace and deleted with it; and, where address validation was used, the validation result with the address, which is deleted with the customer concerned, with the workspace, or at the latest 120 days after the check (210 days for an invalid address).

11. Information and audits

Custilo makes available to the Customer the information necessary to demonstrate compliance with article 28 of the GDPR. It allows for and contributes to audits, including inspections, by the Customer or an independent auditor it mandates, who is bound by confidentiality. An audit is announced at least 30 days in advance, takes place during business hours, is limited to once a year (unless a supervisory authority requires it or after a personal data breach), does not disrupt the Service or give access to other customers’ data, and is at the Customer’s expense. Custilo may first answer by providing documentation, including its sub-processors’ certifications and audit reports.

12. Liability and duration

Each party’s liability under this DPA is subject to the limitations of the Terms, without prejudice to the rights of data subjects under article 82 of the GDPR. These limitations do not apply to intentional or gross fault, or to processing outside the Customer’s instructions. This DPA applies for as long as Custilo processes Customer Personal Data. It is governed by Belgian law, and disputes are settled as provided in the Terms.

Annex 1. Description of the processing

  • Subject matter and purpose: collecting feedback from the Customer’s customers on the Customer’s behalf: storing customers and their interactions (events), sending feedback request emails, recording scores and comments, showing results and segments, sending alerts on low scores to the people the Customer chooses, exporting data, and optionally checking that email addresses exist before sending.
  • Nature of the processing: collection, storage, organisation, consultation, analysis, transmission by email, export and erasure.
  • Data subjects: the Customer’s customers (and their contact persons), and the people the Customer adds as alert recipients.
  • Categories of personal data: email address; name, the Customer’s own customer reference and language, if provided; details of the interaction as chosen by the Customer (for example date, location, type of service, salesperson, order or job reference); email delivery status and unsubscribe status; feedback scores and free text comments; the email address and confirmation status of alert recipients; technical data from visits to the response and unsubscribe pages (IP address, browser, and a pseudonymised form of the IP address used for rate limiting).
  • Special categories: none intended. Free text comments are written by the data subjects themselves and could contain any information.
  • Frequency: continuous, for as long as the Customer uses the Service.
  • Duration and retention: for the duration of the Agreement, until the Customer deletes the data or the workspace, as described in section 10.

Annex 2. Technical and organisational security measures

  • Tenant isolation: every workspace’s data is separated by row level security enforced in the database itself, covered by automated tests that check one workspace cannot read another’s data.
  • Access control: role based access within a workspace (owner, admin, analyst, viewer), enforced in the database. Access by Custilo staff is limited to what is needed for operation and support.
  • Authentication and secrets: passwords are stored as one way hashes by the authentication provider; API keys, invitation tokens and confirmation tokens are stored as hashes only; survey response links use random, opaque tokens that contain no identifiers.
  • Encryption: all connections use TLS; data is stored with encryption at rest provided by the database hosting provider.
  • Abuse protection: rate limits on public pages and the API, and the authentication provider’s limits on sign in; email addresses can be validated before sending; unsubscribes, hard bounces and spam complaints stop further emails.
  • Data minimisation and retention: automatic deletion of expired operational data (such as invitations, validation results and rate limit records); full deletion of a workspace 30 days after it is deleted.
  • Monitoring: application logs and error monitoring to detect and fix incidents.
  • Sub-processors: selected for their security practices and bound by data processing agreements.