AvomuSoftware & Sound
Home Products Services About Contact Get started
Data processing

Data Processing Addendum

Last updated: 24 July 2026

In plain English: When you are a business customer and we run a service that holds personal data for you, this page is the rulebook for how we handle that data. You stay in charge of the data. We only do what you tell us to do, we keep it safe, and we help you meet your duties under the GDPR.

This Data Processing Addendum (the "Addendum" or "DPA") is part of our Terms of Service. It applies whenever Avomu (KvK 76757579), Havenstraat 68, 2871 EA Schoonhoven, Netherlands, processes personal data on your behalf while we provide our products or services - for example when we host a SaaS app for you or run a service that stores data about your users or contacts. If anything in the Terms of Service and this Addendum clash on a data protection point, this Addendum wins.

Contents
  1. Who is who (roles)
  2. What we process
  3. Our promises as a processor
  4. Subprocessors
  5. Sending data abroad
  6. Data subject requests
  7. Personal data breaches
  8. Audits and information
  9. End of service
  10. Liability
  11. Getting a signed copy
  12. Which law applies

1. Who is who (roles)

Under the GDPR (the EU's General Data Protection Regulation) there are two main roles, and they matter here:

  • You, the customer, are the "data controller". You decide why and how the personal data is used. It is your data and your call.
  • Avomu is the "data processor". We handle the data for you and only do what your instructions and the law allow.

A few simple definitions used on this page:

  • Personal data is any information about a living person who can be identified - a name, email address, IP address, and so on.
  • Processing means anything done with that data - storing it, showing it, changing it, backing it up, or deleting it.
  • Data subject is the person the data is about.
  • GDPR is the European data protection law that both of us follow.

2. What we process

We only process the personal data that is needed to provide the service to you. In short:

  • What data: the personal data your service needs to work - for example account details, contact details and content your users add.
  • Whose data: your own users, customers, staff or contacts.
  • How long: for as long as we provide the service, plus a short wind-down period.
  • On whose orders: your documented instructions. Using the service, and the settings you choose, count as your instructions. You can also send us written instructions.

We do not use your personal data for our own purposes, and we never sell it.

3. Our promises as a processor

When we handle personal data for you, we promise to:

  • Follow your instructions. We only process the data on your documented instructions and as the law requires. If a law forces us to do something else, we will tell you first, unless that law stops us.
  • Keep it confidential. We keep your data private and make sure the people who work on it are bound by a duty of confidentiality.
  • Keep it secure. We use appropriate technical and organisational security measures to protect the data. You can read more in our Security Policy.
  • Help you answer people. We help you respond to data subjects who want to see, correct, delete or move their data.
  • Help you stay compliant. We help you with security, breach notifications and data protection impact assessments where you reasonably need it.
  • Warn you of breaches. If we learn of a personal data breach, we tell you without undue delay so you can act.

4. Subprocessors

To run the service we may use other trusted companies, called "subprocessors", to help us. Typical categories are:

  • Hosting - the servers and cloud that store and run the service.
  • Email delivery - sending service and notification emails.
  • Payment processing - taking payments where the service needs it.

We can provide the current list of named subprocessors on request - just email [email protected] and we'll share who we use.

Before any subprocessor touches your data, we put a written contract in place that holds them to the same kind of data protection duties we owe you. We stay responsible to you for the work they do. If we want to add or change a subprocessor, we will tell you beforehand so you have a fair chance to object.

5. Sending data abroad

We aim to keep your personal data inside the European Economic Area (the "EEA"). If any data needs to go outside the EEA, we make sure it is protected with a proper safeguard - for example a European Commission "adequacy decision" (which says a country's protection is strong enough) or the European Commission's Standard Contractual Clauses.

6. Data subject requests

Sometimes a person will contact us directly to ask about their data - for example to see a copy or to have it deleted. Because you are the controller, we do not answer for you. Instead we pass the request on to you without undue delay, and we help you respond the way the law requires.

7. Personal data breaches

A "personal data breach" means data being lost, exposed or changed when it should not be. If one happens on our side, we:

  • investigate what went wrong;
  • act to limit the harm and put things right; and
  • tell you without undue delay, with the details you reasonably need, so you can meet your own duty to notify regulators or the people affected.

8. Audits and information

You can check that we are keeping our word. We give you the information you reasonably need to show that we follow this Addendum, and we allow reasonable audits or inspections under sensible conditions - with fair notice, during normal working hours, without disrupting other customers, and with respect for confidentiality and security.

9. End of service

When the service ends, you choose what happens to the personal data we hold for you: we will either delete it or return it to you. After that we delete the copies we still hold, unless a law says we must keep some of it for a set time.

10. Liability

Our responsibility under this Addendum follows the same limits set out in our Terms of Service. Nothing here removes any responsibility that cannot be removed under the mandatory law of the Netherlands.

11. Getting a signed copy

Need a signed DPA for your records? Email us at [email protected] or [email protected] and we will arrange one.

12. Which law applies

This Addendum is governed by the law of the Netherlands, and any dispute is for the competent Dutch courts. Please read it together with our Privacy Policy and Security Policy.

AvomuSoftware & Sound

We build software and cloud apps you can trust, and sound that people remember. A registered Dutch studio.

[email protected] · [email protected]

Explore

  • Products
  • Services
  • About
  • Contact

Legal

  • Legal notice
  • Privacy policy
  • Terms of service
  • Cookie policy
  • Disclaimer

Policies

  • Acceptable use
  • Refunds & cancellation
  • Service levels & support
  • Security
  • Data processing (DPA)
  • Accessibility

© 2026 Avomu · Netherlands · All rights reserved.

Software · SaaS · Music production