This Data Processing Agreement (“DPA”) forms part of the agreement between Alboweb B.V., trading as Chief Tools, and the customer using a service covered by this DPA. It is comprised of Part 1, the Data Pro Statement, and Part 2, the Standard Clauses for Data Processing.
Data Processing Agreement
How Chief Tools processes personal data on behalf of customers using our account-based services.
Version 2026-08-01 · Published
Part 1
Data Pro Statement
Along with the Standard Clauses for Data Processing, this Data Pro Statement constitutes the data processing agreement for the products and services described below.
General information
1. Data processor and privacy contact
This Data Pro Statement was drawn up by Alboweb B.V., trading as Chief Tools, with its registered postal address at Titus Brandsmahove 52, 2717 TG Zoetermeer, the Netherlands (“Data Processor”).
If you have any queries about this Data Pro Statement or data protection in general, contact us at privacy@chief.app, call +31 (0)85 06 05 456, or use our contact page.
2. Effective date, version and revisions
This Data Pro Statement has version number 2026-08-01 and enters into force for customers first accepting the Terms on or after August 1, 2026. For customers who already had an account, it enters into force on September 1, 2026.
We regularly revise the security measures described in this Data Pro Statement to ensure that we remain prepared and up to date with regard to data protection. Revised versions will be published on this page. We will notify customers of significant revisions through our regular service communication channels, including email where appropriate. The termination right in Article 2.2 of the Standard Clauses applies to significant revisions.
3. Products and services
This Data Pro Statement applies to Domain Chief, Cert Chief, Deploy Chief, Tny, Bill.do, FlowGuard, Backup Chief and Socket Chief (the “Covered Services”), but only to the extent Chief Tools processes personal data on a customer’s behalf through a Covered Service. Account administration, billing, service analytics, fraud prevention, legal compliance, communications with customers and management of the business relationship are outside this DPA and are described in our Privacy Policy.
4. Description of the products and services
The Covered Services are account-based tools for domain management, certificate monitoring, deployments, shortened links, cloud-cost reporting, traffic protection, backup automation and real-time event delivery. Annex 1 describes each Covered Service and its processing in more detail.
5. Intended use
The Covered Services are designed and built to process the types of personal data described in Annex 1 for the purposes determined by the customer. The customer or its customer determines the purposes and essential means of processing and acts as controller. Chief Tools acts as processor or subprocessor and processes that personal data only under the customer’s instructions.
The processing of special categories of personal data and personal data relating to criminal convictions and offences was not taken into account when the Covered Services were designed. Such data must not be submitted. Domain Chief may process government-issued or registration identifiers where a registry or registrar requires them to establish eligibility or register a domain. The customer must determine whether a Covered Service is appropriate for its intended processing.
6. Privacy by design and privacy by default
Chief Tools supports privacy by design and privacy by default through data minimisation, logical separation between customer teams, access controls, authentication safeguards and service-appropriate retention and deletion. Annex 2 describes the applicable measures. The customer remains responsible for determining its processing purposes, configuring and using the Covered Services appropriately, limiting the personal data it submits and assessing whether the available settings and measures meet its own obligations.
7. Standard Clauses
Data Processor uses the Standard Clauses for Data Processing included in Part 2 of this DPA.
8. Processing outside the EU or EEA
Data Processor processes personal data partly outside the EU or EEA. Depending on the recipient and transfer, Data Processor relies on an adequacy decision, the EU-US Data Privacy Framework for an eligible recipient, the European Commission’s Standard Contractual Clauses with supplementary measures where appropriate, or another lawful GDPR Chapter V safeguard. The applicable processing locations and safeguards are identified on the Subprocessors page.
9. Subprocessors
Data Processor uses the subprocessors listed on the Subprocessors page. For each subprocessor, that page describes its role, where it processes personal data and the arrangements used to protect transfers outside the EU or EEA.
Data Processor will give Client at least 30 days’ advance notice by email before a new subprocessor starts processing Personal Data for a Covered Service. Client may submit a reasoned objection during that period. The parties will work in good faith to resolve the objection. If no reasonable solution is available, Client may terminate the affected Covered Service before the change takes effect.
10. Support with requests from data subjects
Data Processor supports customers by providing available functionality through which personal data can be accessed, corrected, exported or deleted. The customer should use that functionality first. Where the customer cannot reasonably fulfil a request through the Covered Service, Data Processor will, following a reasonable request and taking account of the nature of the processing, provide assistance through our contact page. If Data Processor is approached directly by a data subject about personal data processed for a customer, Data Processor will refer the data subject to that customer where possible.
11. Support with Data Protection Impact Assessments
If the customer is required to carry out a Data Protection Impact Assessment or a subsequent consultation within the meaning of Articles 35 and 36 of the GDPR, Data Processor will cooperate following a reasonable request, taking account of the nature of the processing and the information available to Data Processor.
12. Deletion following termination
Once the Agreement for a Covered Service has been terminated, Data Processor will delete the personal data it processes on behalf of the customer in accordance with the customer’s choice under item 13. Personal data will be deleted from active systems after the applicable return period and no later than 90 days after termination. Residual backup copies are not used for ordinary processing and expire within 90 days after deletion from active systems. If a backup is restored for disaster recovery, the deletion will be reapplied.
13. Returning personal data following termination
At the customer’s choice, Data Processor will either return the customer’s personal data in a commonly used, machine-readable format and then delete it, or delete it without return. The customer may communicate this choice before termination or within 30 days afterward through our contact page. During that period, processing is restricted to storage, security, legal compliance and carrying out the customer’s instruction. If the customer gives no other instruction during that period, the customer instructs Data Processor to delete the personal data. A customer-confirmed request to delete an account, team or Covered Service is an instruction to delete the associated personal data without return or a further return period, so the customer should obtain any desired export before confirming that request.
Security policy
14. Security measures
Data Processor has implemented the technical and organisational measures described in Annex 2 to protect the Covered Services. Annex 2 explains the treatment of pseudonymisation and encryption and the measures used to support confidentiality, integrity, availability, resilience and restoration following an incident.
15. Information Security Management System
Data Processor applies risk-based security-management practices but does not represent that these practices constitute a certified Information Security Management System. Unless expressly stated in writing, Data Processor does not claim conformity with ISO 27001, ISO 27701, an NLdigital ISMS or an equivalent standard.
Data breach protocol
17. Notification of personal data breaches
If Data Processor discovers a personal data breach affecting personal data processed for a customer, it will notify the customer without undue delay through the customer’s primary account contact or another appropriate direct channel. The notification will include the nature of the breach; the categories and approximate number of affected data subjects and records where available; the likely consequences; measures taken or proposed to address and mitigate the breach; and a contact point for further information. Information may be supplied in phases when it is not available at the same time. The customer or its customer remains responsible for deciding whether notifications must be made to the Dutch Data Protection Authority, another supervisory authority or affected data subjects.
Part 2
Standard Clauses for Data Processing
Version: March 2025
Along with the Data Pro Statement, these Standard Clauses for Data Processing constitute the data processing agreement. They also constitute an annex to the Agreement and to the appendices to the Agreement, including any general terms and conditions which may apply.
Article 1. Definitions
The following terms have the following meanings in these Standard Clauses for Data Processing, the Data Pro Statement and the Agreement:
1.1 Dutch Data Protection Authority (AP): the supervisory authority defined in Article 4(21) of the GDPR.
1.2 GDPR: the General Data Protection Regulation.
1.3 Data Processor: the party which, in its capacity as an ICT supplier, processes Personal Data on behalf of its Client as part of the performance of the Agreement.
1.4 Data Pro Statement: the statement issued by Data Processor in which it provides information such as the intended use of its products or services, security measures which have been implemented, subprocessors, data breaches, certification and dealing with the rights of Data Subjects.
1.5 Data Subject: an identified or identifiable natural person.
1.6 Client: the party on whose behalf Data Processor processes Personal Data. Client can either be the controller, which determines the purpose and means of the processing, or another data processor.
1.7 Agreement: the agreement concluded between Client and Data Processor, based on which the ICT supplier provides services or products to Client and of which this data processing agreement forms part.
1.8 Personal Data: all information relating to an identified or identifiable natural person, as defined in Article 4(1) of the GDPR, processed by Data Processor as required under the Agreement.
1.9 Data Processing Agreement: these Standard Clauses for Data Processing which, together with Data Processor’s Data Pro Statement or similar information, constitute the data processing agreement within the meaning of Article 28(3) of the GDPR.
Article 2. General provisions
2.1 These Standard Clauses for Data Processing apply to all Personal Data processing operations carried out by Data Processor in providing its products and services, as well as to all Agreements and offers. The applicability of Client’s data processing agreements is explicitly rejected.
2.2 The Data Pro Statement, and particularly the security measures described in it, may be adapted from time to time to changing circumstances by Data Processor. Data Processor shall notify Client in the event of significant revisions. If Client in all reasonableness cannot agree to the revisions, Client shall be entitled to terminate the Data Processing Agreement in writing, stating its reasons for doing so, within 30 days after receiving notice of the revisions.
2.3 Data Processor shall process the Personal Data on behalf of Client in accordance with the written instructions agreed between Client and Data Processor. Data Processor shall promptly inform Client if, in its opinion, an instruction infringes the GDPR or other applicable EU or EEA data-protection law.
2.4 Client or its customer shall serve as the controller within the meaning of the GDPR, shall have control over the processing of the Personal Data and shall determine the purpose and means of processing the Personal Data.
2.5 Data Processor shall serve as the processor within the meaning of the GDPR and shall therefore not determine the purpose and means of processing the Personal Data and shall not make decisions on the use of the Personal Data and other such matters.
2.6 Data Processor shall implement the GDPR as laid down in these Standard Clauses for Data Processing, the Data Pro Statement and the Agreement. It is up to Client to assess, on the basis of this information, whether Data Processor is providing sufficient guarantees with regard to the implementation of appropriate technical and organisational measures in order to ensure that the processing operations meet the requirements of the GDPR and that Data Subjects’ rights are sufficiently protected.
2.7 Client shall guarantee Data Processor that it acts in accordance with the GDPR, that it provides a high level of protection for its systems and infrastructure at all times, that the nature, use and processing of the Personal Data are not unlawful and that they do not violate any third party’s rights.
2.8 Administrative fines imposed on Client by the Dutch Data Protection Authority cannot be recovered from Data Processor.
Article 3. Security
3.1 Data Processor shall implement the technical and organisational security measures set out in its Data Pro Statement. In implementing the technical and organisational security measures, Data Processor shall take into account the state of the art and the costs of implementation, as well as the nature, scope, context and purposes of the processing and the intended use of its products and services, and the risks of varying likelihood and severity to the rights and freedoms of Data Subjects that are to be expected considering the nature of the intended use of Data Processor’s products and services.
3.2 Unless explicitly stated otherwise in the Data Pro Statement, the products and services provided by Data Processor shall not be equipped to process special categories of personal data or data relating to criminal convictions and offences.
3.3 Data Processor seeks to ensure that the security measures it implements are appropriate for the manner in which Data Processor intends its products and services to be used.
3.4 In Client’s opinion, those security measures provide a level of security that is tailored to the risk inherent in the processing of the Personal Data used or provided by Client, taking into account the factors referred to in Article 3.1.
3.5 Data Processor shall be entitled to adjust the security measures it has implemented if, in its discretion, this is necessary for the continued provision of an appropriate level of security. Data Processor shall record any significant adjustments it chooses to make, for example in a revised Data Pro Statement, and shall notify Client of those adjustments where relevant.
3.6 Client may request Data Processor to implement further security measures. Data Processor shall not be obliged to honour such requests to adjust its security measures. If Data Processor makes any adjustments to its security measures at Client’s request, Data Processor is entitled to invoice Client for the costs associated with those adjustments. Data Processor shall not be required to implement the requested security measures until both Parties have agreed upon them in writing.
Article 4. Data breaches
4.1 Data Processor does not guarantee that its security measures shall be effective under all circumstances. If Data Processor discovers a personal data breach within the meaning of Article 4(12) of the GDPR, it shall notify Client without undue delay. The Data Breach Protocol in the Data Pro Statement outlines the way in which Data Processor shall notify Client of personal data breaches.
4.2 It is up to the controller, whether Client or its customer, to assess whether the personal data breach of which Data Processor has notified the controller must be reported to the Dutch Data Protection Authority or to the Data Subject concerned. The controller shall at all times remain responsible for reporting personal data breaches which must be reported to the Dutch Data Protection Authority or Data Subjects pursuant to Articles 33 and 34 of the GDPR. Data Processor is not obliged to report personal data breaches to the Dutch Data Protection Authority or to the Data Subject.
4.3 Where necessary, Data Processor shall provide further information on the personal data breach and shall assist Client to meet its breach-notification requirements within the meaning of Articles 33 and 34 of the GDPR by providing all necessary information available to Data Processor.
4.4 If Data Processor incurs reasonable costs in doing so, it is entitled to invoice Client for those costs at the rates applicable at the time.
Article 5. Confidentiality
5.1 Data Processor shall ensure that the persons processing Personal Data acting under its authority have committed themselves to confidentiality.
5.2 Data Processor shall be entitled to provide third parties with Personal Data if and insofar as this is necessary due to a court order, statutory provision or order issued by a competent government authority.
5.3 Any and all access or identification codes, certificates, information regarding access or password policies provided by Data Processor to Client, and any and all information provided by Data Processor to Client detailing the technical and organisational security measures included in the Data Pro Statement are confidential and shall be treated as such by Client and disclosed only to authorised employees of Client. Client shall ensure that its employees comply with the requirements described in this Article.
Article 6. Term and termination
6.1 This Data Processing Agreement constitutes part of the Agreement and any new or subsequent agreement arising from it, enters into force at the time of the conclusion of the Agreement and shall remain effective for an indefinite period.
6.2 This Data Processing Agreement shall end by operation of law upon termination of the Agreement or upon termination of any new or subsequent agreement arising from it between the Parties.
6.3 If the Data Processing Agreement is terminated, Data Processor shall delete all Personal Data it currently stores and which it has obtained from Client within the timeframe laid down in the Data Pro Statement, in such a way that the Personal Data can no longer be used and shall have been rendered inaccessible. Alternatively, where this has been agreed in the Data Pro Statement, Data Processor shall return the Personal Data to Client in a machine-readable format.
6.4 If Data Processor incurs costs associated with Article 6.3, it shall be entitled to invoice Client for those costs. Further arrangements relating to this subject can be laid down in the Data Pro Statement.
6.5 Article 6.3 does not apply if Data Processor is prevented from removing or returning the Personal Data in full or in part by a statutory provision. In such instances, Data Processor shall continue to process the Personal Data only insofar as necessary by virtue of its statutory obligations. Article 6.3 also does not apply if Data Processor is the controller of the Personal Data within the meaning of the GDPR.
Article 7. The rights of Data Subjects, Data Protection Impact Assessments and auditing rights
7.1 Where possible, Data Processor shall cooperate with reasonable requests made by Client relating to Data Subjects who invoke their rights against Client. If Data Processor is directly approached by a Data Subject, it shall refer the Data Subject to Client where possible.
7.2 If Client is required to carry out a Data Protection Impact Assessment or a subsequent consultation within the meaning of Articles 35 and 36 of the GDPR, Data Processor shall cooperate following a reasonable request to do so.
7.3 Data Processor shall cooperate with Client’s requests for the deletion of Personal Data insofar as Client cannot carry this out itself.
7.4 Data Processor may, if available, demonstrate compliance with its requirements under the Data Processing Agreement by means of a valid Data Processing Certificate or an equivalent certificate or audit report issued by an independent expert.
7.5 In addition, at Client’s request, Data Processor shall provide all other information that is reasonably required to demonstrate compliance with the arrangements made in this Data Processing Agreement. If, in spite of the foregoing, Client has grounds to believe that the Personal Data are not processed in accordance with the Data Processing Agreement, Client shall be entitled to have an audit performed, at its own expense, no more than once every year by an independent, certified, external expert who has demonstrable experience with the type of processing operations carried out under the Agreement. The audit shall be limited to verifying that Data Processor is complying with the arrangements regarding the processing of Personal Data set out in this Data Processing Agreement. The expert shall be subject to a duty of confidentiality with regard to its findings and shall notify Client only of matters which cause Data Processor to fail to comply with its obligations under the Data Processing Agreement. The expert shall provide Data Processor with a copy of its report. Data Processor shall be entitled to reject an audit or instruction issued by the expert if, in Data Processor’s discretion, the audit or instruction is inconsistent with the GDPR or any other law, or constitutes an unacceptable breach of the security measures Data Processor has implemented.
7.6 The Parties shall consult each other on the findings of the report at their earliest convenience. The Parties shall implement the measures for improvement suggested in the report insofar as they can reasonably be expected to do so. Data Processor shall implement proposed measures for improvement insofar as, in its discretion, they are appropriate, taking into account the processing risks associated with its product or service, the state of the art, the costs of implementation, the market in which it operates and the intended use of the product or service.
7.7 Data Processor shall be entitled to invoice Client for any costs it incurs in implementing the measures referred to in this Article.
Article 8. Subprocessors
8.1 Data Processor has specified in the Data Pro Statement whether it uses any third parties, or subprocessors, to help process the Personal Data and, if so, which third parties.
8.2 Client authorises Data Processor to engage other subprocessors to meet its obligations under the Agreement.
8.3 Data Processor shall notify Client of any changes concerning the addition or replacement of the third parties engaged by Data Processor, for example through a revised Data Pro Statement. Client shall be entitled to object to such changes. Data Processor shall ensure that any third parties it engages commit to ensuring the same level of Personal Data protection as the security level Data Processor is bound to provide to Client pursuant to the Data Pro Statement.
Article 9. Other provisions
These Standard Clauses for Data Processing, along with the Data Pro Statement, constitute an integral part of the Agreement. Therefore, any and all rights and obligations arising from the Agreement, including any applicable general terms and conditions or limitations of liability, shall also apply to the Data Processing Agreement.
Annexes
Service details and security measures
Annex 1: Processing details
Processing lasts for the term of the relevant service and the deletion period described in the Data Pro Statement. The frequency is continuous or as initiated by the customer and its users.
| Service | Purpose and data | Data subjects and retention |
|---|---|---|
| Domain Chief | Domain, DNS, redirect and mail configuration; registrant name, organisation, postal address, email, telephone number and registration eligibility identifiers; verification and activity records. | Customer users, registrants and administrative or technical contacts. Active data until deletion or termination; backups within 90 days. Registrars and registries apply their own legal retention. |
| Cert Chief | Domains, IP addresses, public certificate, TLS, HTTP and DNS scan results, and notification contacts or endpoints for certificate monitoring. | Customer users, technical contacts and website operators. Configuration until deletion; individual test runs normally up to three months; backups within 90 days. |
| Deploy Chief | Repository and project metadata, commit authors, server configuration and keys, encrypted environment values, scripts, deployment logs and provider OAuth tokens for automated deployments. | Customer users, developers and commit authors. Active data until Customer deletes it or terminates the service; backups within 90 days. |
| Tny | URLs, slugs, comments, custom domains, webhooks, open-graph data, uploaded files, IP addresses, referrers, user agents and derived country data for links and traffic analytics. | Customer users and visitors who follow links. Retained according to the configured feature or plan; active data until deletion and backups within 90 days. |
| Bill.do | Connected DigitalOcean account details, resources, invoices, usage and spend information, and encrypted provider tokens for cost reporting. | Customer users, account owners and invoice contacts. Active data until disconnection or termination; backups within 90 days. |
| FlowGuard | IP addresses, request paths and metadata, selected headers, rule and action logs, IP lists, comments and alert destinations for traffic analysis and protection. | Customer users and visitors to protected services. Searchable event data is retained according to plan settings, normally no more than 30 days; configuration until deletion; backups within 90 days. |
| Backup Chief | Backup source and destination configuration and encrypted storage credentials to stream encrypted backups to customer-selected storage. | Customer users and people represented in customer-selected backup content. Chief Tools retains configuration until removal; the customer controls backup content and retention at its destination; Chief Tools backups expire within 90 days. |
| Socket Chief | Application, channel and webhook configuration, event payloads and connection metadata for real-time delivery. | Customer users and people represented in submitted events. Live events are transient; the latest payload may be cached where configured; settings remain until deletion and backups expire within 90 days. |
Annex 2: Technical and organisational measures
- TLS protects supported network communications in transit.
- Passwords are hashed, and multi-factor authentication and passkeys are available for accounts.
- Personal Data is not generally pseudonymised because the Covered Services often need the original identifiers, content or configuration to perform the customer’s instructions. Data minimisation, logical separation and access restrictions are used instead.
- Chief Tools does not represent that ordinary Personal Data is encrypted at rest across every Covered Service. Selected sensitive credentials are application-encrypted at rest. Other Personal Data is protected by access controls, logical separation and the safeguards of the relevant hosting or storage provider.
- Logical access controls and team isolation restrict Personal Data to authorised users and services.
- Production access is limited according to operational need and protected by authentication and confidentiality obligations.
- Confidentiality and integrity are supported through access controls, system and dependency maintenance, logging, monitoring and tenant separation.
- Error monitoring, operational alerts and backups support detection, investigation, continuity and restoration after an incident. Backup coverage, frequency and restoration arrangements vary by Covered Service. Unless a separate service-level agreement states otherwise, no fixed availability, recovery-point or recovery-time objective applies.
- Systems, dependencies and access are maintained and reviewed on a risk-based basis.
- Subprocessors are assessed for their role, location, contractual protection and security relevance before use.