Itjoe
ENNL

01

Roles and scope

1.1. The Customer is the controller for the personal data of Participants. Itjoe is the processor. 1.2. This data processing agreement applies to all processing Itjoe carries out for the Customer in delivering the Platform. It belongs to the main agreement and follows Article 28 GDPR.

02

Subject, duration, nature and purpose

2.1. Subject: delivering online training to the Customer's Participants through the Platform. 2.2. Duration: as long as the main agreement runs, plus the period afterwards until all data has been deleted in accordance with Article 12.

2.3. Nature and purpose: creating and managing accounts, offering training, tracking progress and certificates, running assessments, showing aggregated management information to the Customer, securing the Platform, and Itjoe's own internal analysis and market research to improve the training. Never for anything else, and never shared with third parties outside Itjoe. 2.4. The categories of data subjects and personal data are listed in Annex 1.

03

Instructions

3.1. Itjoe processes personal data solely on the Customer's written instructions. The functionality of the Platform counts as the agreed instruction. 3.2. If Itjoe considers an instruction to be in breach of the GDPR, Itjoe reports this immediately and does not carry out the instruction until there is clarity. 3.3. If Itjoe is legally required to disclose data, Itjoe informs the Customer beforehand, unless the law prohibits this.

04

What Itjoe explicitly does not do

This article is a guarantee, not an intention. Itjoe makes no connection to Microsoft Graph, the tenant or any other part of the Customer's IT environment. Itjoe has no access to Participants' documents, mail, calendars or chats and processes only what a Participant enters in the closed learning environment.

Itjoe does not record working time and does not calculate a productivity score. Progress per Participant (completed parts, level, room to improve) is tracked, for training advice and for the insight the Customer gets under Annex 1. Itjoe never shows the Customer individual answers to assessments; group figures appear only from five Participants per group, and that threshold is fixed in the software and cannot be adjusted. Itjoe does not sell personal data, does not use it for advertising and does not use it to train AI models.

05

Confidentiality

5.1. Everyone processing personal data under Itjoe's responsibility is bound by confidentiality. 5.2. This obligation continues after the end of this data processing agreement.

06

Security

6.1. Itjoe takes appropriate technical and organisational measures as referred to in Article 32 GDPR. The measures are set out concretely in Annex 2. 6.2. The core: storage exclusively within the European Union, mandatory passkeys for administrators, optional single sign-on with Microsoft Entra ID per organisation, and an audit log that keeps login attempts and administrator changes for at least ninety days. 6.3. Itjoe keeps the measures up to date with the state of the art. Itjoe does not lower the level of security during the term.

07

Subprocessors

7.1. The Customer gives Itjoe general written authorisation to engage subprocessors for hosting and email. The current list is in Annex 3. 7.2. Itjoe imposes on every subprocessor at least the same obligations as in this data processing agreement.

7.3. If Itjoe wants to add or replace a subprocessor, Itjoe announces this at least thirty days in advance. The Customer may object in writing, with reasons, within that period. If the parties cannot reach agreement, the Customer may terminate the main agreement as of the date the change takes effect, with a proportionate refund of the amount paid in advance. 7.4. Itjoe remains fully responsible for the work of subprocessors.

08

Data breaches

8.1. If Itjoe discovers a personal data breach, Itjoe reports it to the Customer without undue delay, and no later than 48 hours after discovery. 8.2. The report contains what the Customer needs for any notification to the Dutch Data Protection Authority and to data subjects: what happened, which data and how many data subjects are affected, the expected consequences, and the measures taken or proposed. If not everything is known yet, Itjoe first reports what is known and supplements it afterwards.

8.3. Itjoe never reports a breach to the Dutch Data Protection Authority or to data subjects itself. That is and remains the Customer's role. 8.4. Itjoe documents every breach and cooperates with the Customer's investigation.

09

Rights of data subjects

9.1. If Itjoe receives a request from a Participant about access, correction, deletion or another GDPR right, Itjoe forwards that request to the Customer within five working days. 9.2. Itjoe assists the Customer with reasonable technical and organisational means to handle such requests within the statutory period. 9.3. Itjoe also assists the Customer, insofar as reasonably possible, with obligations under Articles 32 to 36 GDPR, such as a data protection impact assessment.

10

Verification and audits

10.1. On request, Itjoe demonstrates that the arrangements are being met. That starts in writing: a current description of the security measures and, where relevant, an export from the audit log. 10.2. If that is demonstrably insufficient, the Customer may have an audit carried out at most once a year, itself or through an independent expert who is not a competitor of Itjoe, announced thirty days in advance.

10.3. The audit disrupts the service as little as possible. Each party bears its own costs. The findings are confidential. 10.4. After a security incident or an instruction from the supervisory authority, the limit of once a year does not apply.

11

Transfers outside the EEA

11.1. Itjoe processes and stores personal data exclusively within the European Union. 11.2. Transfer to a country outside the European Economic Area only takes place with the Customer's prior written consent and with appropriate safeguards under Chapter V of the GDPR.

12

Retention, return and deletion

12.1. After the Licence Period, the environment is deactivated. Participants and administrators no longer have access from that point. 12.2. On the Customer's request, Itjoe provides an export of the personal data in a common format before deactivation.

12.3. On deactivation, Itjoe deletes Participants' account data and all login data. Itjoe keeps only the data needed for the validity of the certificate: name, certificate number and whether the training was completed. 12.4. At the Customer's earlier request, Itjoe deletes the data sooner.

13

Liability

13.1. Liability is governed by the arrangement in the main agreement, including the limitations it contains. 13.2. Nothing in this article limits the rights of data subjects under Article 82 GDPR.

14

Duration, precedence and final provisions

14.1. This data processing agreement applies as long as Itjoe processes personal data for the Customer. 14.2. In the event of conflict with the main agreement, this data processing agreement prevails insofar as it concerns the processing of personal data. 14.3. Dutch law applies. 14.4. The Dutch text is binding; the English translation is provided for convenience.

Annex 1: which data, and what for

Data subjects are employees of the Customer with an account and administrators with access to the dashboard. We process no special categories of personal data: the Platform does not ask for them and does not need them.

  • Name, work email, organisation, role and teamAccount and access
  • Progress per module and certificate statusThe training itself and the dashboard
  • Certificate date and verification codeIssuing and verifying certificates
  • Answers to the baseline, follow-up and intake assessmentsMeasuring whether the training works; visible to the Customer in aggregate only, from five Participants
  • Practical assignment submissions and feedback on themAssessment and learning effect
  • Weekly goal, saved prompts and favouritesThe Participant's personal learning environment
  • Login data: password hash, passkey registration, recovery codesSecure access
  • Audit log: timestamp, actor, action, IP address and browserSecurity and accountability
  • Organisation logo (uploaded by an administrator)Display on the certificate and in the environment

After the environment is deactivated (Article 12), Itjoe keeps only name, certificate number and whether the training was completed from this table; the remaining data is then deleted.

Annex 2: security measures

  • All data is stored and processed within the European Union; connections are encrypted (TLS).
  • Administrators always log in with a passkey; a password alone is not enough for administrators. Single sign-on with Microsoft Entra ID is optional per organisation and can be made mandatory for Participants; without SSO, Participants log in with a username and password.
  • Single sign-on uses a dedicated app registration per organisation; the associated secret is stored encrypted. Accounts are never created automatically.
  • Access is role-based: a Participant only sees their own data, a Customer administrator only their own organisation.
  • After five failed login attempts, an account is blocked for fifteen minutes. The same limit applies to recovery codes.
  • An audit log records login attempts, failed attempts and all administrator changes, with timestamp, actor, IP address and browser. It is kept for at least ninety days and is exportable as CSV.
  • Privacy by design: the Platform technically cannot reach the Customer's IT environment. There is no integration to switch off. Aggregation of assessment results starts only from five Participants per group; that threshold is one fixed value in the software.

Ready to sign, or questions first?

Request the signable version, including the current subprocessor list (Annex 3). Your privacy officer is also welcome to grill us first. We respond within two working days.