Data processing agreement
Version 3 — effective 3 September 2026
Dorelli Cloud is a product of Dorelli Hosting, handelsnaam van Uitgeverij Doreleijers. This data processing agreement forms part of the terms and conditions of Dorelli Hosting, handelsnaam van Uitgeverij Doreleijers and applies as soon as we process personal data on your instructions. You are the controller; we are the processor.
1. Subject matter
We host and maintain your website. In doing so we process personal data submitted through or stored on that website. We do this solely to provide the service we agreed with you, and for as long as that agreement lasts.
2. Data and data subjects
Depending on your website this typically concerns data of visitors and customers that you collect: name, email address, phone number, contact form messages, and technical data such as IP addresses in log files. We do not process special categories of personal data unless agreed in writing in advance.
2a. Contact forms
If your site carries one of our contact forms, we send the submission straight to you and do not keep its content. We record only that something was sent — which site, a hashed IP address and the time — to block spam, and erase that after two days. The messages themselves therefore sit in your mailbox, not with us; retaining and answering them is your responsibility.
2b. Apps and databases
If your application runs in a container with us (App and usage-based plans), we process everything that application stores in its database, storage or cache solely on your instructions. Which personal data that is, and whose, is up to you; we do not look inside unless you ask us to or it is necessary to resolve an incident. The data lives with our sub-processor Microsoft within the EU (Amsterdam region for containers and storage, Dublin region for databases). After deletion we keep databases and storage for thirty days (an own database server for seven days) and then erase them permanently; the start page of a new app is screened once automatically for abuse via Anthropic (article 7).
3. We act on your instructions
We process personal data only on your instructions and for the purposes above. We do not use it for our own purposes and do not sell it. If a law requires otherwise, we will notify you beforehand unless that law prohibits it.
4. Confidentiality
Everyone on our side with access to your data is bound by confidentiality. Access is granted only to those who need it to deliver the service.
5. Security
We take appropriate technical and organisational measures: encrypted traffic (HTTPS/TLS), hashed password storage, access on a need-to-know basis, bot protection on forms, continuous monitoring and daily backups retained for ninety days. We keep these measures current with the state of the art.
6. Sub-processors
We engage other parties to deliver the service. Currently these are Microsoft (Azure, hosting within the EU), Cloudflare (DNS, security, email forwarding and sending), Mollie (payments, Netherlands) and Anthropic (the automated abuse check on new trial sites only; your customer data is not sent there). Data processing agreements with at least the same level of protection are in place with each. If we wish to add or replace a sub-processor we will notify you in advance; if you disagree, you may terminate the agreement.
7. Transfers outside the EU
We store your data within the European Union. The data we process on your instructions — your website, your database, your backups, the submissions through your forms — does not leave the EU. Only for a new trial site on a dorelli.cloud subdomain is the visible text of that site sent to Anthropic for the abuse check; that happens before there is a customer relationship and does not touch your data. That transfer is covered by the European Commission's standard contractual clauses. Should we wish to process personal data outside the EU beyond this, we will inform you in advance.
8. Data subject rights
If you receive a request for access, correction, deletion or portability, we will help you handle it within a reasonable period. If such a request reaches us directly, we forward it to you and do not answer it ourselves.
9. Data breaches
If we discover a personal data breach we notify you without undue delay, with the information you need to assess whether you must report it to the Dutch Data Protection Authority and to data subjects. Reporting to the supervisory authority is your responsibility as controller. You can reach us at [email protected].
10. Audits
On request we provide the information needed to demonstrate compliance with these arrangements. If you wish to carry out an audit, announce it at least two weeks in advance; the costs are yours unless the audit shows we fall short.
11. End of the agreement
After termination we delete the personal data within thirty days, or return it to you first if you ask. Data we are legally required to keep, such as invoices, is retained for the duration of that obligation.