Back to Security & trust

    Data Processing Agreement

    Iconicorp, trading as Selectronyx
    Processor terms for personal data you put into FairSpec. This document is for your counsel to review. It is not legal advice.
    Last updated: 19 September 2026
    Parties. The customer ("Controller") and Iconicorp, trading as Selectronyx, KvK 96235950, Berg 112, 5508 AZ Veldhoven, Netherlands ("Processor"). Contact: privacy@selectronyx.com.

    1. Scope and roles

    This agreement applies only where Selectronyx processes personal data on the customer's documented instructions in the FairSpec application: BOM content the customer uploads or generates, and account data of the customer's own users. For that processing the customer is the controller and Selectronyx is the processor.

    It does not apply where Selectronyx is the controller — site visitors, enquiries, Selectronyx billing records, and Selectronyx marketing. Those activities are described in the Privacy Policy.

    2. Article 28(3) terms

    The Processor shall:

    1. process personal data only on documented instructions from the Controller, including with regard to transfers, unless required to do so by Union or Member State law;
    2. ensure that persons authorised to process the personal data have committed themselves to confidentiality;
    3. take all measures required pursuant to Article 32 GDPR (security of processing), as described on the Security & trust page;
    4. respect the conditions for engaging another processor in section 3;
    5. taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights;
    6. assist the Controller in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to the Processor;
    7. at the choice of the Controller, delete or return all personal data after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage;
    8. make available to the Controller all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.

    The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data-protection provisions.

    3. Sub-processors

    The Controller authorises the Processor to engage the sub-processors listed at /platform/sub-processors, which is incorporated by reference and may change without amending this agreement. The Processor shall impose data-protection obligations on each sub-processor equivalent to those in this agreement.

    The Processor will give the Controller at least 30 days' notice of any intended addition or replacement of a sub-processor. Write to privacy@selectronyx.com to join that notification list. The Controller may object in writing during the notice period. If the parties cannot resolve an objection, the Controller may terminate the affected services.

    4. International transfers

    Transfers to the United States occur for the providers marked as such in the sub-processor register. Where a provider is certified under the EU-U.S. Data Privacy Framework, that certification may currently be relied on. This agreement does not rest on the DPF alone.

    The Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), are annexed to this agreement as Annex 2 and apply to restricted transfers. In the event of conflict, the SCCs prevail over this document on the transfer.

    5. Breach

    The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach, and shall provide the information reasonably required for the Controller to meet Article 33 GDPR.

    6. Duration and law

    This agreement lasts for the term of the FairSpec services and survives as needed to delete or return data. It is governed by the laws of the Netherlands. The competent courts are those of the Netherlands.

    Annex 1 (description of processing) is the FairSpec app data described in section 1. Annex 2 is Decision (EU) 2021/914 Module Two, incorporated by reference. Annex 3 is the live register at /platform/sub-processors.

    Annex 2 — Standard Contractual Clauses

    The parties enter into the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor). Docking clause: optional. Governing law of the Clauses: the Netherlands. Competent supervisory authority: Autoriteit Persoonsgegevens.

    The Clauses apply to restricted transfers of the personal data described in Annex 1 to sub-processors outside the EEA listed in Annex 3, including where a Data Privacy Framework certification is also relied on. The official text of the Clauses is the Commission decision linked above; it is not restated here.