Data Processing Agreement

This Data Processing Agreement forms part of the HappyClient Terms and Conditions (section 28) and applies automatically to every business customer using the Services. No signature is needed. A countersigned copy for your records is available on request via privacy@thehappyclient.com.

Parties

This Data Processing Agreement is entered into between:

  • the Customer, the business that accepts the HappyClient Terms and Conditions, hereinafter the "Controller", and
  • HappyClient BV, with registered office at Coupure Rechts 88, 9000 Ghent, Belgium, registered under company number BE 1022.204.608, hereinafter the "Processor",

together the "Parties".

Article 1: Subject matter and duration

1.1. This agreement governs the processing of personal data by the Processor on behalf of the Controller in the context of HappyClient's services: collecting, processing, editing and making available video, audio and text testimonials (testimonials and interviews) via the HappyClient platform, in accordance with Article 28 of Regulation (EU) 2016/679 ("GDPR").

1.2. This agreement applies for as long as the underlying service agreement is in force and for as long as the Processor processes personal data on behalf of the Controller.

Article 2: Nature, purpose and scope of the processing

2.1. The details of the processing (categories of data subjects, categories of personal data, purposes) are described in Annex 1.

2.2. The Processor processes the personal data only on documented instructions from the Controller and only to deliver the agreed services, unless required to do so by Union or Member State law to which the Processor is subject; in such a case, the Processor informs the Controller of that legal requirement before processing, unless that law prohibits such information.

2.3. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.

Article 3: Confidentiality

3.1. The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

3.2. The Processor acknowledges that the mere identity of a data subject as a client of the Controller is also confidential information, and treats it as such.

Article 4: Security

The Processor takes all technical and organisational measures required under Article 32 GDPR. An overview of the current measures is set out in Annex 3.

Article 5: Sub-processors

5.1. The Controller hereby gives a general written authorisation for the engagement of the sub-processors listed in Annex 2.

5.2. The Processor informs the Controller of any intended addition or replacement of sub-processors, giving the Controller the opportunity to object on reasoned grounds within 14 days. If a well-founded objection is not resolved within a reasonable period, the Controller may terminate the affected services free of charge.

5.3. The Processor imposes on each sub-processor the same data protection obligations as set out in this agreement and remains fully liable to the Controller for the performance of the sub-processor's obligations.

Article 6: Transfers outside the EEA

Insofar as a sub-processor processes personal data outside the European Economic Area, the Processor ensures that the transfer takes place on the basis of a valid transfer mechanism within the meaning of Chapter V GDPR, including the standard contractual clauses of the European Commission (SCCs) and/or an adequacy decision (including the EU-U.S. Data Privacy Framework for recipients certified under it). Annex 2 states the processing location and the applicable mechanism for each sub-processor.

Article 7: Assistance to the Controller

7.1. Taking into account the nature of the processing, the Processor assists the Controller in fulfilling its obligation to respond to requests from data subjects (access, rectification, erasure, restriction, portability, objection). Requests that reach the Processor directly are forwarded to the Controller without delay.

7.2. The Processor assists in ensuring compliance with the obligations under Articles 32 to 36 GDPR (security, notification of personal data breaches, data protection impact assessment), taking into account the nature of the processing and the information available to the Processor.

Article 8: Notification of personal data breaches

The Processor notifies the Controller of a personal data breach without undue delay, and at the latest within 48 hours of becoming aware of it, via the contact point designated by the Controller, with all information the Controller reasonably needs for any notification to the Data Protection Authority and the data subjects. Questions and notifications to the Processor go to privacy@thehappyclient.com.

Article 9: Deletion and return

9.1. At the end of the services, the Processor, at the choice of the Controller, deletes all personal data or returns it in a common, machine-readable format, within 30 days, and deletes existing copies, unless storage is required by law.

9.2. In addition, during the term of this agreement, the Processor deletes specific data (including raw recordings after delivery of the finished videos) upon simple request of the Controller, within 30 days of the request.

Article 10: Audit and information

10.1. The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations of Article 28 GDPR, and allows for audits, conducted by the Controller, an auditor mandated by the Controller or the competent supervisory authority, subject to reasonable prior notice and at most once a year save where there are indications of non-compliance. The costs of an audit are borne by the Controller, save where non-compliance is established.

10.2. The Processor maintains a record of processing activities in accordance with Article 30(2) GDPR.

Article 11: Liability

The liability of the Parties under this agreement is subject to the limitations and exclusions of liability in the underlying service agreement between the Parties or, failing that, in the Processor's general terms and conditions. This is without prejudice to the liability of the Parties towards data subjects under Article 82 GDPR.

Article 12: Governing law and competent court

This agreement is governed by Belgian law. Disputes are submitted to the courts of the judicial district of Ghent. Supervisory authority: the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit, GBA).

Annex 1: Details of the processing

Annex 2: Sub-processors

The current list of sub-processors and their locations is published at thehappyclient.com/subprocessors; changes are announced there at least 14 days in advance. As at 8 October 2026 it reads:

Sub-processors that process participant data

Sub-processors that only process account and billing data of platform users

Annex 3: Technical and organisational measures (TOMs)

  • Encryption of all data in transit (TLS 1.2+); encryption at rest at the cloud providers used.
  • Access to the platform via authenticated accounts, separated per customer organisation (organisation scoping); internal access management on a least-privilege basis.
  • Video processing in a shielded cloud environment in the EU (Google Cloud, Belgium region); secrets managed via Google Secret Manager (EU replication).
  • Media made accessible via unique, non-guessable URLs; a video is only published at the customer's initiative.
  • Error and security monitoring (EU hosting); logging of processing activities.
  • Explicit consent step for every participant before a recording is submitted; consent can be withdrawn via privacy@thehappyclient.com.
  • Backups and recovery facilities via the cloud providers used.

Version 1.0, effective 8 October 2026.

Changes

  • 8 October 2026: Version 1.0 published. The DPA forms part of the HappyClient Terms and Conditions and applies to every business customer without a signature.