Data processing agreement
Last updated: 28 juli 2026
When you use Solven, Solven processes personal data on your behalf. This data processing agreement describes the arrangements for that in line with Article 28 GDPR. It forms part of the agreement between you (the customer) and Solven.
Data controller
Solven Systems (“Solven”)
Gevestigd te Almere (Nederland) — volledig adres op aanvraag
Chamber of Commerce: 66754755 · VAT: NL195767081B03
Email: info@solvensystems.nl · Data Protection Officer: not appointed (not legally required for our size)
1. Roles
The Customer is the controller for the personal data it enters into the platform (for example about its own customers and staff). Solven is the processor and processes this data solely on the Customer’s instructions.
2. Subject and duration
The processing concerns the provision of the Solven platform. It lasts for as long as the agreement is in force.
3. Nature, purpose and categories
- Nature and purpose: providing and managing the Service (incl. CRM, scheduling, work orders, invoicing, collection).
- Categories of data subjects: the Customer’s customers, contacts and staff.
- Categories of data: contact and address data, job and invoice data and other data entered by the Customer.
4. Instructions
Solven processes the data only in accordance with the Customer’s documented instructions, unless a legal obligation requires otherwise.
5. Confidentiality and security
Solven binds persons with access to confidentiality and takes appropriate technical and organisational measures, including encryption, role-based access, tenant isolation, two-factor authentication and logging.
6. Sub-processors
The Customer gives general authorisation for engaging sub-processors (e.g. for hosting, payments and accounting integrations). Solven imposes the same obligations on sub-processors and informs the Customer of intended changes. Current list: our hosting provider, Mollie (payments), our e-mail delivery provider, Anthropic (AI, if enabled) and — at the Customer’s initiative — Exact Online or Moneybird.
7. Data-subject rights
Solven provides the Customer with reasonable assistance for data-subject requests (such as access, rectification, erasure and portability), to the extent the Customer cannot handle these itself via the platform.
8. Data breaches
Solven informs the Customer without undue delay after becoming aware of a personal data breach, with the information the Customer needs to meet its notification obligations.
9. Return and deletion
After the agreement ends, Solven deletes or returns the personal data, at the Customer’s choice, subject to any statutory retention obligation. The Customer can also export data itself via the platform.
10. Audits
On request, Solven makes available the information needed to demonstrate compliance with Article 28 GDPR and cooperates with reasonable audits, within the framework agreed in the contract.