GDPR Data-Processing Statement

This statement forms part of the Terms when you (the “Customer”) use Contaktly to process personal data of EEA/UK residents.

  1. Roles – Customer is the Data Controller; Sales Boutique B.V. is the Data Processor.
  2. Subject matter & duration – processing chat transcripts and meeting details for the duration of the Customer’s subscription.
  3. Nature & purpose – capture visitor enquiries, qualify leads, schedule meetings.
  4. Types of data – names, e-mail addresses, company names, chat content, meeting times.
  5. Data subjects – website visitors and Customer personnel.
  6. Processor obligations
  • Process data only on documented instructions.
  • Ensure confidentiality via NDAs and least-privilege access.
  • Implement appropriate technical and organisational measures (encryption, backups, logging).
  • Assist Controller with data-subject requests.
  • Notify Controller of any personal-data breach without undue delay.
  • Delete or return personal data upon termination (erase endpoint).
  1. Sub-processing – Sub-processors listed above; Controller will be notified of changes with 14 days’ notice.
  2. Audits – On reasonable notice, Controller may audit compliance once per year or after a data breach.
  3. Governing law – Dutch law; courts of Amsterdam.

Sign up for your free account