Data processing agreement (DPA)
Last updated: 26 August 2026 · v1.1
1. Roles
The Customer (practice) is the controller; Traucare is the processor. Traucare processes personal data solely on the instructions of the Customer.
2. Subject matter and duration
This data processing agreement forms part of the subscription and applies for as long as Traucare processes data on behalf of the Customer.
3. Security measures
Traucare takes appropriate technical and organisational measures, including encryption of sensitive fields, tenant isolation through Row-Level Security, mandatory 2FA and immutable logging. These measures are set up in line with the NEN 7510 guidelines; certification is in preparation.
4. Sub-processors
Traucare only engages sub-processors that offer the same level of protection. No US sub-processors are used. An up-to-date list is available on request.
5. Data location
All personal data is stored and processed within the European Union, with a hosting partner in Germany. No data is transferred outside the EEA.
6. Data breaches
In the event of a (suspected) data breach, Traucare informs the Customer without undue delay, providing the information needed to notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
7. Termination
Upon termination, Traucare exports or deletes the data at the Customer's choice, in accordance with the agreed retention periods.
This English version is a translation provided for convenience. In case of any discrepancy, the Dutch version prevails.