Skip to content
Aqlemy

Legal

Data processing agreement

Our role as processor of personal data on behalf of your organization.

Version 2026.2In force since October 1, 2026

Table of Contents

Legal Notice

This Data Processing Agreement is drawn up pursuant to GDPR Article 28 and broadly follows the structure of the Model Data Processing Agreement for Digital Educational Resources and Privacy, the sector standard for Dutch education. Dutch law applies. In the event of conflict between language versions, the Dutch text prevails.

This Data Processing Agreement ("DPA") is drawn up pursuant to article 28 of the General Data Protection Regulation (GDPR) between: Kirca IT Services, Chamber of Commerce number 91781418, VAT number NL004915794B15, established in Amsterdam, trading under the name Aqlemy, hereinafter the "Processor"; and the organisation registered on the Platform, hereinafter the "Controller"; together the "Parties". Why this DPA exists. The Controller determines the purposes and means of processing the personal data of its members, students, parents and teachers. The Processor processes that data solely on its instructions. Article 28(3) GDPR requires that relationship to be set out in writing; this DPA is that record. When it applies. This DPA applies as soon as the Controller registers on or uses the Platform, and continues for as long as that processing continues. No separate signature is required; acceptance is recorded with a version number, a timestamp and a checksum of the text, by the same route as the Terms of Service. Order of precedence. This DPA prevails over the Terms of Service and over any other arrangement between the Parties, for everything concerning the processing of personal data. That order is non-negotiable: a data processing agreement that can be set aside by general terms does not satisfy article 28 GDPR. For all other matters — price, term, availability, support — the Terms of Service apply. The annexes. Three annexes form an integral part of this DPA: - Annex A — Processing register: per processing activity the purpose, the categories of data and data subjects, and the retention period (article 23). - Annex B — Security annex: the technical and organisational measures, ordered by availability, integrity and confidentiality (article 24). - Annex C — Sub-processors and transfers: the reference to the current register and what it states per party (article 25). Alignment with the sector standard. This DPA broadly follows the structure of the Model Data Processing Agreement for Digital Educational Resources and Privacy, the standard widely used in Dutch education: a main text with a privacy annex and a security annex as appendices, an audit arrangement with a third-party statement, and a liability clause that does not allow the contractual limitation to be invoked against a recourse action under article 82 GDPR. We are not a signatory to the Dutch Privacy Covenant for Digital Educational Resources and claim so nowhere; we have adopted its structure because that structure does what it is meant to do. Languages. This DPA is available in Dutch, Turkish, English and Arabic. In the event of conflict, the Dutch text prevails.

Personal data: any information relating to an identified or identifiable natural person (GDPR art. 4(1)). Processing: any operation performed on personal data, including collecting, recording, organising, storing, updating, altering, retrieving, consulting, using, disclosing, erasing or destroying (GDPR art. 4(2)). Controller: the organisation that uses the Platform and determines the purposes and means of processing the personal data of its members, students, parents and teachers. Processor: Kirca IT Services, trading as Aqlemy, which processes personal data on behalf of the Controller. Sub-processor: a third party engaged by the Processor to process personal data on behalf of the Controller. Data subject: the natural person to whom the personal data relates. Personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed (GDPR art. 4(12)). Security incident: an event affecting security without it being established that personal data is involved. Not every security incident is a personal data breach. Supervisory authority: the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), or the competent authority in another member state. Platform: the management platform operated by the Processor, including the administration portal, the mobile applications, the public organisation pages and the information screens. Main Agreement: the service agreement between the Parties, consisting of the order or registration and the Terms of Service. Annex: an annex to this DPA, as listed in article 1. In writing: on paper or by electronic means, including email and a notice in the administration portal, provided the content can be stored and reproduced. Business Day: Monday through Friday, excluding public holidays generally recognised in the Netherlands.

Contact

Aqlemy (Kirca IT Services)KVK: 91781418
This document is drawn up in accordance with GDPR Article 28 and other applicable data protection legislation. The three annexes — the processing register, the security annex and the sub-processor register — form an integral part of this agreement.