This Data Processing Agreement forms part of the HappyClient Terms and Conditions (section 28) and applies automatically to every business customer using the Services. No signature is needed. A countersigned copy for your records is available on request via privacy@thehappyclient.com.
Parties
This Data Processing Agreement is entered into between:
- the Customer, the business that accepts the HappyClient Terms and Conditions, hereinafter the "Controller", and
- HappyClient BV, with registered office at Coupure Rechts 88, 9000 Ghent, Belgium, registered under company number BE 1022.204.608, hereinafter the "Processor",
together the "Parties".
Article 1: Subject matter and duration
1.1. This agreement governs the processing of personal data by the Processor on behalf of the Controller in the context of HappyClient's services: collecting, processing, editing and making available video, audio and text testimonials (testimonials and interviews) via the HappyClient platform, in accordance with Article 28 of Regulation (EU) 2016/679 ("GDPR").
1.2. This agreement applies for as long as the underlying service agreement is in force and for as long as the Processor processes personal data on behalf of the Controller.
Article 2: Nature, purpose and scope of the processing
2.1. The details of the processing (categories of data subjects, categories of personal data, purposes) are described in Annex 1.
2.2. The Processor processes the personal data only on documented instructions from the Controller and only to deliver the agreed services, unless required to do so by Union or Member State law to which the Processor is subject; in such a case, the Processor informs the Controller of that legal requirement before processing, unless that law prohibits such information.
2.3. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.
Article 3: Confidentiality
3.1. The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.2. The Processor acknowledges that the mere identity of a data subject as a client of the Controller is also confidential information, and treats it as such.
Article 4: Security
The Processor takes all technical and organisational measures required under Article 32 GDPR. An overview of the current measures is set out in Annex 3.
Article 5: Sub-processors
5.1. The Controller hereby gives a general written authorisation for the engagement of the sub-processors listed in Annex 2.
5.2. The Processor informs the Controller of any intended addition or replacement of sub-processors, giving the Controller the opportunity to object on reasoned grounds within 14 days. If a well-founded objection is not resolved within a reasonable period, the Controller may terminate the affected services free of charge.
5.3. The Processor imposes on each sub-processor the same data protection obligations as set out in this agreement and remains fully liable to the Controller for the performance of the sub-processor's obligations.
Article 6: Transfers outside the EEA
Insofar as a sub-processor processes personal data outside the European Economic Area, the Processor ensures that the transfer takes place on the basis of a valid transfer mechanism within the meaning of Chapter V GDPR, including the standard contractual clauses of the European Commission (SCCs) and/or an adequacy decision (including the EU-U.S. Data Privacy Framework for recipients certified under it). Annex 2 states the processing location and the applicable mechanism for each sub-processor.
Article 7: Assistance to the Controller
7.1. Taking into account the nature of the processing, the Processor assists the Controller in fulfilling its obligation to respond to requests from data subjects (access, rectification, erasure, restriction, portability, objection). Requests that reach the Processor directly are forwarded to the Controller without delay.
7.2. The Processor assists in ensuring compliance with the obligations under Articles 32 to 36 GDPR (security, notification of personal data breaches, data protection impact assessment), taking into account the nature of the processing and the information available to the Processor.
Article 8: Notification of personal data breaches
The Processor notifies the Controller of a personal data breach without undue delay, and at the latest within 48 hours of becoming aware of it, via the contact point designated by the Controller, with all information the Controller reasonably needs for any notification to the Data Protection Authority and the data subjects. Questions and notifications to the Processor go to privacy@thehappyclient.com.
Article 9: Deletion and return
9.1. At the end of the services, the Processor, at the choice of the Controller, deletes all personal data or returns it in a common, machine-readable format, within 30 days, and deletes existing copies, unless storage is required by law.
9.2. In addition, during the term of this agreement, the Processor deletes specific data (including raw recordings after delivery of the finished videos) upon simple request of the Controller, within 30 days of the request.
Article 10: Audit and information
10.1. The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations of Article 28 GDPR, and allows for audits, conducted by the Controller, an auditor mandated by the Controller or the competent supervisory authority, subject to reasonable prior notice and at most once a year save where there are indications of non-compliance. The costs of an audit are borne by the Controller, save where non-compliance is established.
10.2. The Processor maintains a record of processing activities in accordance with Article 30(2) GDPR.
Article 11: Liability
The liability of the Parties under this agreement is subject to the limitations and exclusions of liability in the underlying service agreement between the Parties or, failing that, in the Processor's general terms and conditions. This is without prejudice to the liability of the Parties towards data subjects under Article 82 GDPR.
Article 12: Governing law and competent court
This agreement is governed by Belgian law. Disputes are submitted to the courts of the judicial district of Ghent. Supervisory authority: the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit, GBA).
Annex 1: Details of the processing
| Topic | Details |
|---|---|
| Nature and purpose | Collecting video, audio and text testimonials via a branded online interview flow; professional editing and subtitling; making the finished videos and derived content assets available via the HappyClient platform. |
| Categories of data subjects | Persons invited by the Controller to record a testimonial (customers, experts, partners, employees); platform users of the Controller. |
| Categories of personal data | Name, email address, job title/organisation; video and audio recordings; transcripts and subtitles; consent given by the data subject; technical log data. |
| Special categories | The data subject determines the content of their testimonial; the Processor does not process special categories of personal data as such and does not use biometric identification. |
| Retention period | Finished videos and metadata: for as long as the services are provided. Raw recordings: up to 24 months after delivery, then deletion, unless the Controller requests earlier deletion (Art. 9.2) or requests longer retention in writing. |
Annex 2: Sub-processors
The current list of sub-processors and their locations is published at thehappyclient.com/subprocessors; changes are announced there at least 14 days in advance. As at 8 October 2026 it reads:
Sub-processors that process participant data
| Sub-processor | Role | Location / region | Transfer mechanism |
|---|---|---|---|
| Vercel Inc. (US) | Hosting of web applications; storage of raw video uploads | EU (Frankfurt) | DPA + SCCs (US parent company) |
| Google Cloud (Google Ireland Ltd) | Video processing and secrets management | EU, Belgium region (europe-west1) | Within the EEA |
| Cloudflare Inc. (US) | Storage of processed media (finished videos, audio, thumbnails) | Western Europe (WEUR) | DPA + SCCs |
| Upstash Inc. (US) | Session database (name, email, consent, answers, transcripts) | EU, AWS eu-central-1 (Frankfurt) | DPA + SCCs (US parent company) |
| OpenAI LLC (US) | AI transcription and subtitle correction/translation | US | DPA + SCCs; API data is not used for model training |
| OpenRouter Inc. (US) | AI text processing of transcripts (summaries, labels), via Google models | US | DPA + SCCs |
| Resend Inc. (US) | Transactional email notifications | US | DPA + SCCs |
| PostHog Inc. | Product analytics (no session recording) | EU hosting | Within the EEA |
| Functional Software Inc. (Sentry) | Error logging | EU hosting (Germany) | Within the EEA |
Sub-processors that only process account and billing data of platform users
| Sub-processor | Role | Location / region | Transfer mechanism |
|---|---|---|---|
| Clerk Inc. (US) | Authentication of platform users (interview participants do not need to log in) | US | DPA + SCCs |
| Neon Inc. (US) | Database for organisation and platform metadata (no participant data) | EU, AWS eu-central-1 (Frankfurt) | DPA + SCCs (US parent company) |
| Stripe Payments Europe Ltd. (IE) | Payment processing for invoicing | EU (Ireland); transfer to Stripe Inc. (US) possible | DPA + SCCs |
Annex 3: Technical and organisational measures (TOMs)
- Encryption of all data in transit (TLS 1.2+); encryption at rest at the cloud providers used.
- Access to the platform via authenticated accounts, separated per customer organisation (organisation scoping); internal access management on a least-privilege basis.
- Video processing in a shielded cloud environment in the EU (Google Cloud, Belgium region); secrets managed via Google Secret Manager (EU replication).
- Media made accessible via unique, non-guessable URLs; a video is only published at the customer's initiative.
- Error and security monitoring (EU hosting); logging of processing activities.
- Explicit consent step for every participant before a recording is submitted; consent can be withdrawn via privacy@thehappyclient.com.
- Backups and recovery facilities via the cloud providers used.
Version 1.0, effective 8 October 2026.
Changes
- 8 October 2026: Version 1.0 published. The DPA forms part of the HappyClient Terms and Conditions and applies to every business customer without a signature.