Skip to main content
Comptelogicza

Data processing agreement

Last updated: 5 October 2026

This English version is a courtesy translation. The Dutch version is the legally binding text. Verwerkersovereenkomst

In brief

  • Applies when we process personal data for you, such as speakers' voices or names in scripts.
  • We use the material only for your production and follow your written instructions.
  • After 6 months, or sooner on request, everything is deleted.
  • We report a data breach to you within 48 hours of discovering it.

01Parties and scope

This agreement is between the client (controller) and Comptelogicza B.V., Czaar Peterstraat 148, 1018 PR Amsterdam, KvK 85932008, represented by Sanne de Vries (processor). It forms part of every job for music recording, voice-over, mixing or mastering in which we process personal data of people other than the client, and supplements the terms and conditions. Where they conflict on data protection, this agreement prevails.

This English text is provided for information; the Dutch version is legally binding.

02Subject and nature of processing

Processing overview
Data subjectsVoice actors, singers, musicians, interviewees and people named in scripts
DataVoice recordings, names, character names, speakers' contact details and script content
OperationsRecording, editing, mixing, mastering, storing, delivering and deleting
DurationLength of the job plus a 6-month archive

We only process special categories of data if the client tells us in writing beforehand and we agree additional measures together.

03Client instructions

We process the data only on documented instructions, including the booking confirmation and the client's emails. We do not use the material for our own purposes, as a demo or for training software. If we believe an instruction breaches the GDPR, we say so straight away. The client makes sure speakers and other data subjects are informed and that a valid legal basis exists.

04Confidentiality and staff

Only the engineers working on the production have access, and they are bound by confidentiality. Currently these are Sanne de Vries, Joris Bakker and Marieke Jansen. Visitors to the studio never see material from other clients.

05Security measures

  • Encrypted workstations and backup drives in a locked room.
  • Separate project folders per client.
  • File exchange through encrypted download links with limited validity.
  • Website and email over encrypted connections, hosted by TransIP B.V. in the EU.

We review these measures at least once a year and adjust them when technology or risks call for it.

06Sub-processors

The client gives general authorisation for TransIP B.V. (Schipholweg 9B, 2316 XB Leiden, Nederland) as hosting provider. We engage other sub-processors only after written notice, after which the client may object within 14 days. Each sub-processor is bound by the same obligations. Recorded material is not transferred outside the EEA unless the client asks for it.

07Data subject rights and assistance

If a data subject contacts us, for example a speaker who wants a recording removed, we forward the request to the client within 5 working days and carry out the client's instruction. We also assist, within reason, with a data protection impact assessment or questions from the Dutch Data Protection Authority.

08Data breaches

If we discover a personal data breach, such as a lost drive or a download link sent to the wrong person, we notify the client within 48 hours via [email protected] or by phone. We describe what happened, which data is affected and what we are doing about it. The client decides whether to report the breach to the Autoriteit Persoonsgegevens.

09Termination, return and deletion

After delivery we keep the material for 6 months and then delete it. On request we first hand over all files and delete them sooner, with written confirmation. Statutory retention duties, such as for invoices, still apply.

10Audit, liability and governing law

We provide the client with the information needed to demonstrate compliance and cooperate with a reasonable audit announced at least 14 days in advance. Liability follows the terms and conditions, insofar as the GDPR allows. Dutch law governs this agreement. This version applies from 5 October 2026. How we handle our own clients' data is described in the privacy policy.