WP Citadel

Data Processing Agreement (DPA)

Last updated: March 11, 2026

1. Definitions

2. Subject matter and duration

This DPA applies to all processing of personal data performed by the Processor on behalf of the Controller through the WP Citadel service. The agreement remains in effect for as long as the service is active.

3. Nature and purpose of processing

The Processor processes personal data solely for the purpose of:

4. Types of personal data

5. Categories of data subjects

6. Obligations of the Processor

The Processor shall:

7. Sub-processors

The Processor engages the following sub-processors:

The Controller grants general authorisation for the engagement of sub-processors. The Processor will inform the Controller of any intended changes at least 30 days in advance. The Controller may object to the use of a new sub-processor within 14 days.

8. Data security measures

9. International data transfers

All personal data is stored within the European Union. Sub-processors outside the EU (if any) are covered by the EU–US Data Privacy Framework or Standard Contractual Clauses.

10. Data subject rights

The Processor will assist the Controller in fulfilling requests from data subjects to exercise their rights under GDPR (access, rectification, erasure, restriction, portability, objection). Requests should be sent to contact@wpcitadel.com.

11. Data breach notification

The Processor will notify the Controller without undue delay (within 48 hours) after becoming aware of a personal data breach, providing:

12. Audit rights

The Controller has the right to audit the Processor's compliance with this DPA, subject to reasonable notice (at least 30 days) and confidentiality obligations.

13. Return and deletion of data

Upon termination of the service or upon request, the Processor will delete all personal data within 30 days, unless EU or Member State law requires continued storage.

14. Liability and indemnification

Each party's liability is limited as set out in the Terms of Service. The Processor is liable only for damage caused by processing that violates GDPR obligations specific to processors.

15. Governing law

This DPA is governed by Dutch law and the GDPR. Any disputes will be resolved in accordance with the Terms of Service.

16. Contact

For questions about this DPA or data processing practices, contact: