+31 73 208 0038 Einfach anrufen — Sie sprechen sofort mit einem Mitarbeiter. Kein Menü, keine Warteschlange.

Data processing agreement

This data processing agreement governs how Dysto B.V., trading as QR-Database, as processor handles personal data that you, as controller, process in the Service. It automatically forms part of your agreement with us, in accordance with GDPR Article 28 — no separate signature is required.

Last updated: 19 July 2026.

Parties and context

This data processing agreement applies between Customer (controller) and Dysto B.V., trading as QR-Database (processor), and forms part of the agreement for the use of the Service. By creating an account and using the Service, Customer accepts this data processing agreement.

Subject matter and duration

Dysto processes personal data solely on the instructions of, and for the benefit of, Customer, in order to provide the Service. This data processing agreement applies for the duration of the underlying agreement and automatically ends upon its termination.

Nature and purpose of the processing

The processing consists of storing, consulting and editing data entered into the Service by Customer or its users, for the purpose of managing company assets: registration via QR codes, loan and return registration, inspection management, damage reports, project administration and reporting.

Categories of data subjects and data

The processing relates to: the name and e-mail address of Customer's users; the loan, inspection and damage history of company assets; and — only if Customer enables this itself — contact details of guests upon scanning and location data at the moment of scanning. No special categories of personal data (Article 9 GDPR) are processed, unless Customer itself, without Dysto's knowledge, enters these in free-text fields.

Obligations of the processor

Dysto processes personal data solely on the basis of Customer's written instructions, unless required to do so by law. Dysto ensures that persons processing data under its authority are bound by confidentiality. Dysto never sells personal data and does not use it for its own purposes, including advertising.

Sub-processors

Dysto may engage sub-processors for hosting and related services, provided they offer an equivalent level of protection and a data processing agreement has been concluded with them. All data is stored on servers within the European Union.

An up-to-date overview of sub-processors is available on request via the contact form. Dysto informs Customer of any intended change of sub-processors, so that Customer can object.

Security

Dysto takes appropriate technical and organisational measures to secure personal data against loss or unlawful processing, including encryption of data in transit, role-based access control, and an audit trail of changes. These measures are periodically evaluated and tightened where necessary.

Data breach notification

Dysto informs Customer without undue delay, and no later than 48 hours after Dysto becomes aware of a (suspected) data breach, about the nature, scope and measures taken, so that Customer can, if necessary, report to the Dutch Data Protection Authority and data subjects in time.

Assistance with data subject rights

To the extent reasonably possible, Dysto assists Customer in handling requests from data subjects for access, correction, deletion or data portability. Users can also view and export their own data directly via their profile in the Service.

Inspection and audit

Customer has the right, after prior written notice with a reasonable term, to have Dysto's compliance with this data processing agreement audited, for example on the basis of an audit report or certification provided by Dysto. A physical audit takes place no more than once a year, unless a concrete suspicion of a shortcoming gives cause to do so.

After termination of the processing

Upon termination of the agreement, Dysto gives Customer the opportunity to export all data. After the retention period expires, or at Customer's request, personal data is deleted or anonymised, unless a statutory retention obligation prevents this.

Liability

The liability provisions in Dysto's terms and conditions apply in full to this data processing agreement.

Language

This data processing agreement is available in Dutch and English. In the event of a difference in interpretation between the two versions, the Dutch version prevails.

Opnieuw verbinden met de server...

Verbinden mislukt... nieuwe poging over seconden.

Opnieuw verbinden mislukt.
Probeer het opnieuw of herlaad de pagina.

De sessie is gepauzeerd door de server.

Hervatten van de sessie mislukt.
Probeer het opnieuw of herlaad de pagina.