Data Processing Agreement (DPA)
Last updated: 5th of January 2026
This Data Processing Agreement ("DPA") forms part of the CreateWorker Terms of Service and applies to the processing of personal data by CreateWorker B.V. ("Processor") on behalf of the Organization ("Controller") in connection with the CreateWorker platform and related services (the "Service").
1. Definitions
Capitalized terms not defined in this DPA have the meaning given in the Terms of Service or GDPR.
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" has the meaning set out in Article 4(2) GDPR.
- "Sub-processor" means any third party engaged by Processor to process Personal Data.
2. Scope and Roles
2.1 Roles of the Parties
Controller determines the purposes and means of Processing of Personal Data within the Service.
Processor processes Personal Data solely on behalf of and in accordance with documented instructions from Controller, including as necessary to provide the Service.
2.2 Nature of the Processing
Processing includes collection, storage, use, transmission, and deletion of Personal Data in connection with:
- User authentication and access control
- AI-generated Proposals and approved Executions
- Email ingestion and sending (if enabled)
- Audit logging and monitoring
- Customer support and security
3. Categories of Data Subjects and Personal Data
3.1 Data Subjects
- Employees, contractors, and representatives of Controller
- Email correspondents and business contacts
- Other individuals whose data is submitted by Controller
3.2 Categories of Personal Data
May include, depending on use:
- Names, email addresses, identifiers
- Email content and metadata
- Task inputs and AI outputs
- Audit logs and activity data
Controller determines the categories and content of Personal Data processed.
4. Processing Instructions
Processor shall:
- Process Personal Data only on documented instructions from Controller
- Not process Personal Data for its own purposes
- Inform Controller if an instruction violates applicable data protection law
Use of the Service constitutes Controller's documented instructions.
5. Confidentiality
Processor ensures that persons authorized to process Personal Data are bound by confidentiality obligations.
6. Security Measures
Processor implements appropriate technical and organizational measures to protect Personal Data, including:
- Encryption in transit and at rest
- Role-based access controls
- Audit logging and monitoring
- Secure credential storage
- Environment isolation
Processor may update security measures over time, provided overall protection is not materially reduced.
7. Sub-processors
7.1 Authorization
Controller grants Processor a general authorization to engage Sub-processors.
7.2 Obligations
Processor ensures Sub-processors are subject to contractual obligations no less protective than this DPA.
7.3 List and Changes
A current list of Sub-processors is available via documentation or upon request.
Processor will inform Controller of material changes to Sub-processors where required by law.
8. International Transfers
Where Personal Data is transferred outside the EEA, Processor ensures appropriate safeguards, including:
- Standard Contractual Clauses (SCCs)
- Equivalent lawful transfer mechanisms
9. Assistance with Data Subject Requests
Processor shall, taking into account the nature of the Processing, assist Controller in responding to data subject rights requests.
Where Processor receives a request directly, it shall notify Controller unless legally prohibited.
10. Personal Data Breach
Processor shall notify Controller without undue delay after becoming aware of a Personal Data Breach affecting Customer Data.
Notification will include information reasonably available to Processor at the time.
Processor is not responsible for breaches caused by Controller's systems, credentials, or misuse of the Service.
11. Deletion or Return of Data
Upon termination of the Service:
- Personal Data will be deleted or returned at Controller's choice, subject to legal retention obligations
- Deletion will occur within a reasonable timeframe
12. Audits and Inspections
Controller may audit Processor's compliance with this DPA:
- No more than once per year
- On reasonable prior notice
- During normal business hours
- At Controller's expense
Audits must not unreasonably disrupt operations or compromise security.
Processor may provide third-party reports or summaries in lieu of on-site audits.
13. Liability
Liability arising from this DPA is subject to the limitations set out in the Terms of Service.
Processor is not liable for compliance failures resulting from Controller's instructions or use of the Service.
14. Governing Law
This DPA is governed by the laws of the Netherlands, excluding conflict-of-law principles.
Annex 1 – Processing Details (GDPR Art. 28(3))
Subject Matter:
Provision of AI-assisted workflow orchestration services.
Duration:
For the term of the Service.
Nature and Purpose:
Processing Personal Data to provide, secure, and operate the Service.
Categories of Data Subjects:
As described in Section 3.1.
Categories of Personal Data:
As described in Section 3.2.
Annex 2 – Technical and Organizational Measures
- Encryption at rest and in transit
- Access controls and authentication
- Audit logging and monitoring
- Secure secrets management
- Incident response procedures