Data Processing Agreement (DPA)

Last updated: August 2026

This data processing agreement ("DPA") forms part of the Terms and Conditions of summie B.V. ("summie") and applies as soon as summie processes personal data on behalf of the Customer within the framework of the agreement, as referred to in article 28 GDPR. In the event of any conflict between this DPA and the other Terms and Conditions regarding the processing of personal data, this DPA prevails.

Scope. This DPA applies to summie's Free and Pro tiers. For the Business tier, where summie also processes a connected mailbox, invoice data, and additional banking transaction data, a supplementary agreement with its own DPA applies.

1. Roles

•  The Customer is the controller within the meaning of the GDPR for the personal data it has processed via summie, and has determined the purpose and means of that processing.

•   summie is the processor within the meaning of the GDPR and processes personal data solely on the instructions of and in accordance with the written instructions of the Customer, as set out in this DPA and the agreement.

•   summie has no control over the purpose and means of the processing and makes no independent decisions about the use of the personal data, except as expressly described in article 10 (anonymized data).

2. Processing Instructions

To comply with article 28(3) GDPR, the table below specifies the subject matter, duration, nature, and purpose of the processing, the type of personal data, and the categories of data subjects.

Subject matter and nature of the processing
Storage, AI/OCR extraction, analysis, and management of contract documents and data derived from them via the summie platform

Purpose of the processing
Contract management, reminders before end date/notice period, and (optionally with Pro) integration with an accounting package for relationship recognition

Types of personal data
Names and contact details of contact persons and representatives as stated in uploaded contracts

Categories of data subjects
Employees and representatives of the Customer; contact persons named in the uploaded contracts, such as representatives of suppliers or other counterparties of the Customer

Duration of the processing
For the duration of the agreement between summie and the Customer, subject to article 14 (termination)

summie is not set up for the processing of special categories of personal data or data relating to criminal convictions or offenses, unless the parties have expressly agreed otherwise in writing.

3. Instructions

summie processes personal data solely on the basis of the Customer's written instructions as set out in the agreement and this DPA, and only to the extent necessary to provide the Service. If summie believes that an instruction from the Customer conflicts with the GDPR or other applicable legislation, summie will notify the Customer without undue delay and is entitled to suspend execution of that instruction until the Customer has amended or confirmed it.

4. Security

summie takes appropriate technical and organizational measures to protect personal data against loss or unlawful processing, including at least:

  • Encrypted storage of data and encrypted transmission of data;

  • Access security with strong authentication and role-based access control;

  • Logical separation of environments per Customer, such that one Customer's data is not accessible to another Customer;

  • Logging and monitoring of access to personal data;

  • Active management of security vulnerabilities in the systems managed by summie;

  • Periodic security reviews.

In determining these measures, account has been taken of the state of the art, the costs of implementation, the nature and scope of the processing, and the risks to data subjects. Upon request, summie can provide additional information about the security measures.

5. Data Breaches

If summie discovers a personal data breach that (also) relates to the Customer's data, summie will inform the Customer without undue delay and no later than 48 hours after summie becomes aware of it, with the information available at that time. Under the GDPR, any obligation to notify the Dutch Data Protection Authority and/or data subjects rests with the controller; that is the Customer, not summie. It is therefore up to the Customer to assess whether and how notification must take place. summie will, upon request, provide reasonable cooperation and supply the information the Customer needs to comply with this obligation.

6. Requests from Government Authorities

If summie receives a request from a supervisory authority or a (foreign) government authority regarding the Customer's personal data, summie will: (a) notify the Customer without delay, unless this is not legally permitted; (b) not respond substantively without prior consultation with the Customer, unless legally required; (c) where possible, challenge requests that lack a clear legal basis; and (d) limit its cooperation to what is strictly legally required.

7. Confidentiality

summie ensures that persons who process personal data under its responsibility are bound by a duty of confidentiality. summie will not provide personal data to third parties, unless this is necessary for the performance of the agreement, required by law, or the Customer has given consent for this.

8. Sub-processors

The Customer gives summie general consent to engage sub-processors for the performance of the Service, provided that summie makes written arrangements with these sub-processors that offer at least an equivalent level of protection as this DPA. summie remains fully responsible for its sub-processors' compliance with this DPA. The current sub-processors are:

Cloud hosting (Microsoft Azure) — EU
Storage and hosting of platform data

AI and OCR processing (Microsoft Azure, Google Cloud) — EU
Automatic recognition and extraction of data from contracts

Error monitoring (Sentry) — EU
Detecting and resolving technical errors in the platform

Product analytics (PostHog) — EU
Insight into functional use of the platform for product improvement

Email infrastructure (SendGrid) — US (with EU Standard Contractual Clauses)
Sending notifications (e.g. reminders by email)

Payment provider (Stripe) — US (with EU Standard Contractual Clauses)
Processing subscription payments

Does the Customer connect its own accounting or ERP system (such as Exact Online)? Then summie only reads data from that system, based on the Customer's authorization, without sending data back to that system. In that case, that system processes data in a separate, direct relationship between the Customer and that provider, and does not qualify as a sub-processor of summie.

summie will inform the Customer before engaging a new sub-processor. The Customer may object in writing, with reasons, within 30 days of this notification, on data protection grounds. The parties will then consult in good faith on a solution. If the objection concerns a sub-processor that is essential to the service and summie does not offer an alternative solution within 60 days, the Customer has the right to terminate the entire agreement without notice period or penalty.

9. Rights of Data Subjects

To the extent that the Customer cannot handle this itself via the platform, summie will provide reasonable cooperation with the Customer's requests relating to the rights of data subjects (access, rectification, erasure, restriction, portability, and objection). If summie receives a request directly from a data subject, summie will refer them to the Customer and inform the Customer of this, unless summie is not legally permitted to do so. summie will not provide a substantive response to the data subject without the Customer's prior consent.

10. Anonymized Data and Product Improvement

The Customer acknowledges and agrees that summie has the right to anonymize personal data from Customer Data or, where full anonymization is not reasonably feasible, to pseudonymize it, and to use the resulting data in an aggregated form to improve and further develop the Service — including providing Customers with insights into whether contract terms are in line with the market. This means that identifying characteristics (such as company names, names of contact persons, and exact addresses) are removed or replaced and that data is only used in aggregated form. If the data is demonstrably no longer traceable to an individual contract or individual Customer in this way, it is no longer considered personal data within the meaning of the GDPR. To the extent that this is not demonstrably the case, the data continues to qualify as (pseudonymous) personal data to which the GDPR and this DPA remain applicable, and in that case, summie processes it exclusively for the purposes stated here.

11. AI Processing

summie uses automated OCR and AI techniques to recognize and structure data from contracts. This processing does not involve automated decision-making with legal effects for data subjects within the meaning of Art. 22 GDPR: the output is a tool that is reviewed by the Client before any action is taken. Based on this application (no creditworthiness, recruitment, or jurisprudence), summie does not classify this processing as a high-risk system under the EU AI Act. summie ensures sufficient AI literacy among its staff working with these systems, in accordance with Article 4 of the EU AI Act. summie does not use Client data to train generic third-party AI models. The only exception is the use of anonymized, aggregated data as described in Article 10. The Client remains responsible for verifying data extracted by AI; please also refer to the General Terms and Conditions.

12. Transfers Outside the EEA

Personal data is preferably processed and stored within the EU. For the sub-processors outside the EEA listed in article 8, summie ensures an adequate level of protection through the EU Standard Contractual Clauses or another mechanism recognized by the European Commission. summie will inform the Customer in advance of any new intended transfer outside the EEA that is not already listed in article 8.

13. DPIA and Audit Rights

summie will, at the Customer's reasonable request, cooperate with a data protection impact assessment (DPIA), insofar as this can reasonably be asked of summie.

The Customer has the right, either itself or through an independent third party, to verify whether summie complies with this DPA. To this end, the Customer will first request the available audit reports or certifications from summie. A physical audit is permitted if these documents are inadequate for the purpose of the audit, or if there are well-founded reasons to verify compliance. Instead of a physical audit, summie may provide an annual audit report, provided this meets the Customer's reasonable requirements.

A physical audit must be announced in writing at least 14 days in advance, take place during regular office hours, and must not unreasonably disrupt summie's operations. summie may charge reasonable costs on a cost-price basis for facilitating an audit that lasts longer than 4 hours, unless the audit reveals a shortcoming on summie's part. summie may refuse an expert if, in summie's opinion, they harm summie's competitive position or do not have demonstrable experience with these types of processing.

14. Termination

Upon termination of the agreement, for any reason whatsoever, summie will enable the Customer to export Customer Data in a common, machine-readable format for a period of 90 days. After this period, summie will delete the Customer's personal data in such a way that it can no longer be used or accessed, unless a statutory retention obligation prevents this, in which case summie will continue to retain the data solely for that purpose. Upon request, summie will confirm in writing that the deletion has taken place, with the exception of backups and security logs that are automatically overwritten in accordance with summie's regular policy, no later than 90 days after deletion.

The provisions on confidentiality, liability, and deletion of data remain in force after termination of this DPA as well.

15. Liability

The liability provisions from article 12 of the Terms and Conditions apply in full to this DPA; this DPA contains no additional or different liability regime. summie does not warrant that its security measures will be effective under all circumstances. The Customer is not entitled to recover from summie any administrative fine imposed on the Customer by the supervisory authority, unless such fine is a direct result of an attributable failure by summie to comply with this DPA. Nothing in this DPA limits the direct claims that a data subject may have against summie under article 82 GDPR; such statutory claims by third parties are separate from the contractual limitation of liability between summie and the Customer.

16. Contact

Questions about this DPA, or reporting a (suspected) data breach? Email us at hello@summie.co.