Data Processing Agreement

Version 30 January 2026

This Data Processing Agreement (“DPA”) forms an integral part of the Terms of Service of iotspot B.V ., with its registered office at Veemarktkade 8, 5222 AE ’s-Hertogenbosch, The Netherlands, registered with the Dutch Chamber of Commerce under number 65535294 (“iotspot” or “Processor”). This DPA applies to the processing of Personal Data by iotspot on behalf of its customer (“Customer” or “Controller”) in connection with the provision of the iotspot Smart Workspace Platform Services (“Services”). This DPA is concluded in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR).

1. Subject matter and instructions

1.1 iotspot shall process Personal Data solely for the purpose of providing the Services and in accordance with the documented instructions of the Customer, as set out in this DPA and the applicable Terms of Service.

1.2 iotspot shall not process Personal Data for any other purpose unless required to do so by Union or Member State law.

1.3 The nature and purpose of the processing, categories of Personal Data, and categories of Data Subjects are specified in Annex 1.

2. Roles of the parties

2.1 For the purposes of the GDPR, the Customer acts as Controller and iotspot acts as Processor.

2.2 The Customer warrants that it has a valid legal basis for the processing of Personal Data.

3. Confidentiality

3.1 iotspot shall ensure that persons authorised to process Personal Data are bound by confidentiality obligations.

4. Security of processing

4.1 iotspot shall implement appropriate technical and organisational measures in accordance with Article 32 GDPR.

4.2 Measures include access controls, encryption, network security, logging, and role-based access.

4.3 iotspot commits to maintaining security in line with the state of the art.

5. Use of sub-processors

5.1 The Customer grants iotspot a general authorisation to engage sub-processors.

5.2 iotspot uses Amazon Web Services, Inc. (AWS), with its main storage location in Frankfurt, Germany, and backup storage in Dublin, Ireland.

5.3 iotspot shall ensure sub-processors are bound by equivalent obligations.

5.4 iotspot remains fully liable for sub-processors.

5.5 Customers may object to sub-processor changes on legitimate grounds.

6. International data transfers

6.1 Transfers outside the EEA shall comply with Chapter V GDPR.

6.2 Transfers are safeguarded by EU Standard Contractual Clauses (2021/914) and supplementary measures.

7. Assistance to the Controller

7.1 iotspot shall assist with data subject requests, DPIAs, and supervisory authority consultations.

7.2 Reasonable fees may apply for additional assistance.

8. Personal data breaches

8.1 iotspot shall notify the Customer without undue delay.

8.2 Notifications shall include required GDPR information.

9. Data subject requests

9.1 iotspot shall not respond directly unless authorised.

9.2 Requests received directly shall be forwarded to the Customer.

10. Deletion or return of Personal Data

10.1 Upon termination, Personal Data shall be deleted or returned at the Customer’s choice.

10.2 Deletion shall occur within 45 days unless legally required otherwise.

11. Audits and compliance

11.1 Audits limited to once per year, normal business hours. Customer must provide at least 30 days’ notice for any audit. Any third-party auditor must be mutually agreed upon and bound by confidentiality.

12. Liability

12.1 Liability shall be governed by the Terms of Service.

13. Term

13.1 This DPA remains in effect for the duration of the Services.

14. Governing law and jurisdiction

14.1 This DPA is governed by Dutch law. Disputes shall be submitted to the competent courts where iotspot is established. ANNEX 1 – DESCRIPTION OF PROCESSING Categories of Personal Data

  • Name
  • Business email address
  • Profile information (photo, role, department – optional)
  • Telephone number (optional)
  • LinkedIn URL (optional)
  • Vehicle license plate number (optional)
  • Workspace reservation and usage data
  • Location data derived from workplace reservations (time-limited) Categories of Data Subjects:
  • Employees and contractors of the Customer
  • Visitors, tenants, suppliers, and prospective customers of the Customer