Legal

    Data Processing Agreement

    Last updated: 23 September 2026

    This data processing agreement belongs to the agreement between JB Business Solutions, trading under the name ClientAssist (Processor), and the customer that purchases the ClientAssist service (Controller). It applies from the moment that agreement is concluded, without separate signature, and in the event of a conflict concerning personal data it prevails over the general terms and conditions. If the Controller wants a signed copy, the Processor will send one on request.

    1. Definitions

    Terms such as personal data, processing, data subject, sub-processor and personal data breach have the meaning given to them in the General Data Protection Regulation (GDPR). The Agreement means the agreement concerning the ClientAssist service; the Service means the service described in it.

    2. Subject matter

    2.1 The Processor processes personal data on behalf of the Controller, to the extent necessary to provide the Service. What is processed, of whom, for what purpose and for how long is set out in Annex 1.

    2.2 The Controller determines the purpose and means of the processing. It warrants that it has a legal basis for the processing and that it informs data subjects, including in its own privacy statement.

    3. Instructions

    3.1 The Processor processes the personal data solely on the basis of instructions in writing from the Controller. The Agreement, this data processing agreement and the settings the Controller chooses in the dashboard constitute those instructions.

    3.2 If the Processor is legally required to process personal data otherwise, it will inform the Controller in advance, unless the law prohibits such notification.

    3.3 If the Processor considers that an instruction infringes the GDPR or other privacy legislation, it will notify the Controller immediately.

    3.4 The Processor does not use the personal data for its own purposes, nor to train AI models.

    4. Confidentiality

    Everyone at the Processor who has access to the personal data is bound by confidentiality, through an employment contract, a confidentiality agreement or by law.

    5. Security

    5.1 The Processor takes appropriate technical and organisational measures to secure the personal data, taking into account the state of the art, the costs and the risks to data subjects (article 32 GDPR). Annex 3 describes them.

    5.2 The Processor may adjust the measures, provided the level of security does not decrease.

    6. Sub-processors

    6.1 The Controller gives general authorisation for the engagement of the sub-processors listed in Annex 2.

    6.2 The Processor will notify the Controller by email of a new or replacement sub-processor at least thirty days in advance. The Controller may object on reasonable grounds within that period. If the parties cannot reach agreement, the Controller may terminate the Agreement free of charge with effect from the date on which the sub-processor is engaged.

    6.3 The Processor imposes on each sub-processor at least the same obligations as those set out in this data processing agreement, and remains liable to the Controller for the performance of those obligations.

    7. Transfers outside the European Economic Area

    Some of the sub-processors are established in the United States. The Processor transfers personal data outside the European Economic Area only where a transfer mechanism under Chapter V GDPR applies: the EU-U.S. Data Privacy Framework to the extent the sub-processor is certified under it, and otherwise the Standard Contractual Clauses of the European Commission.

    8. Assistance

    8.1 If a data subject submits a request (for example for access or erasure), the Processor assists the Controller in handling it within the statutory period. If the request is received by the Processor, it forwards it without undue delay.

    8.2 The Processor also assists the Controller with a data protection impact assessment (DPIA), a prior consultation of the Dutch Data Protection Authority and compliance with the security obligation, to the extent these concern the processing under this agreement.

    8.3 For assistance requiring more than a few hours of work, the Processor may charge reasonable costs agreed in advance, unless the assistance is required due to an error by the Processor.

    9. Personal data breaches

    9.1 The Processor notifies the Controller of a personal data breach affecting the Controller's personal data without undue delay, and no later than 48 hours after discovering it.

    9.2 The notification includes, to the extent known: what happened, which data and how many data subjects are affected, the likely consequences, and the measures taken or proposed. The Processor supplements the notification with information that becomes known later.

    9.3 The Controller decides whether the breach is notified to the Dutch Data Protection Authority and the data subjects, and makes that notification itself. The Processor does not contact data subjects unless the Controller requests it or the law requires it.

    10. Audits

    10.1 On request, the Processor makes available to the Controller all information necessary to demonstrate that it complies with this agreement.

    10.2 If that information is insufficient, the Controller may, once a year or after a personal data breach, have an audit carried out by an independent expert who is bound by confidentiality. It announces the audit at least thirty days in advance. The costs are borne by the Controller, unless the audit reveals a material shortcoming on the part of the Processor.

    11. Term and termination

    11.1 This data processing agreement remains in force for as long as the Processor processes personal data on behalf of the Controller.

    11.2 After the end of the Agreement, the Controller may export the personal data or have it returned within thirty days. The Processor then deletes it, including at its sub-processors, unless the law requires it to retain the data for longer. On request, it confirms the deletion in writing.

    11.3 Obligations which by their nature continue, such as confidentiality, remain in force after termination.

    12. Liability

    The liability of the parties under this data processing agreement is governed by article 14 of the general terms and conditions. A fine or compensation imposed on either party is borne by the party to whom the infringement is attributable.

    13. Final provisions

    This data processing agreement is governed by Dutch law. Disputes will be submitted to the District Court of The Hague. In the event of any discrepancy between the Dutch and the English text, the Dutch text prevails.

    Annex 1: specification of the processing

    Nature and purposeAnswering and conducting phone calls and chat conversations on behalf of the Controller; answering questions, scheduling appointments, recording callback requests and transferring calls; displaying conversations, summaries and usage in the dashboard; invoicing based on call duration.
    Data subjectsCallers and website visitors who contact the Controller; employees of the Controller with an account.
    Personal dataCall recording, transcript, summary, phone number, name and other information the data subject provides, date, time and duration of the conversation, appointments and callback requests; for accounts: name, email address and login credentials.
    Special categories of dataAre not knowingly processed. If a caller nevertheless mentions them, for example a health complaint when making an appointment, they end up in the recording and transcript. The Controller assesses whether its use of the Service therefore requires additional measures.
    Retention periodThe content of conversations (recording, transcript, summary, name and phone number of the caller) is deleted no later than 90 days after the conversation, unless the parties agree on a shorter period. Date, time and duration are retained for as long as necessary for invoicing.

    Annex 2: sub-processors

    Sub-processorProcessingLocation
    Retell AI, Inc.Speech recognition and call handlingUS
    Language model provider, via Retell (such as OpenAI)Understanding and answering questionsUS
    ElevenLabsSpeech synthesis (the voice)US
    Twilio Inc.Telephony and phone numbersUS
    Supabase, Inc.Database and storage for the dashboardEU (Ireland)
    Anthropic, PBCLanguage model behind the website chatbot and selection wizardUS

    Annex 3: security measures

    • All connections are encrypted with TLS; the database is stored encrypted.
    • Separation between customers is enforced in the database itself (row-level security): an account sees only the data of its own organisation.
    • Access for the Processor's staff is personal, limited to those who need it for the Service, and runs through separate administrator privileges.
    • Keys and passwords for integrations with sub-processors are stored only on the server, never in the browser.
    • Forms are protected against abuse with rate limiting and spam checks.
    • Conversation content is automatically deleted after the retention period (Annex 1).

    Contact details

    JB Business Solutions

    Trading as ClientAssist

    Jacques Urlusstraat 43

    2202 SN Noordwijk

    The Netherlands

    Chamber of Commerce: 89825802

    VAT: NL004763207B69

    Email: info@clientassist.nl