GDPR

Data Processing Agreement

Version 1.0 — 23 April 2026

This Data Processing Agreement ('DPA') governs how Studio Northstar B.V., trading as Attentico ('Processor'), processes personal data on behalf of customers using Attentico commercially ('Controller') — such as HR teams managing employee birthdays and milestones. This DPA is part of the general terms and takes effect automatically once you use Attentico Work. No separate signature required.

A signed PDF version is available on request for your procurement or legal team. Email dpa@attentico.nl.

1. Parties

The Controller is the organisation purchasing Attentico Work (the customer). The Processor is Studio Northstar B.V. (trading as Attentico), a Dutch private limited company based in The Hague, registered with the Dutch Chamber of Commerce under number 42094999.

2. Subject and duration

This DPA applies to all personal data you process through Attentico — e.g. employee data, birthdays, departments, gift history. It runs for as long as you have an active Attentico account. On termination we delete your data within 30 days, except where statutory retention (e.g. tax records) requires otherwise.

3. Nature and purpose of processing

Attentico processes personal data solely to deliver the service: scheduling gestures, sending gifts and cards, and managing HR gift policy. We do not use your data for marketing, third-party AI model training, or resale. Full stop.

4. Types of data

We do not process special categories (race, religion, health, political views, biometrics) unless you explicitly enter them as a preference — and even then, we ask you to reconsider.

The following categories of personal data may be processed:

  • Identification: full name, work email, department, role
  • Personal milestones: date of birth, work anniversary, start date
  • Delivery details: home address (only if the employee provides it themselves)
  • Preferences: interests, diet, allergies (only when voluntarily entered)
  • Usage data: logins, actions in the app, error messages

5. Attentico's obligations

  • We process data only on your documented instructions (core Attentico functionality counts as such an instruction).
  • Everyone with access to your data is under a duty of confidentiality.
  • We take appropriate technical and organisational measures (see §7).
  • We assist you with data subject requests (access, deletion) within reasonable timeframes.
  • We notify you without undue delay of any data breach — within 24 hours of discovery.
  • On termination we delete all personal data within 30 days, except where law requires otherwise.
  • We cooperate with audits by you or an independent auditor, with reasonable notice.

6. Sub-processors

Attentico works with a small number of carefully selected sub-processors necessary to provide the service. By accepting this DPA you authorise their use. We remain responsible for their actions.

Sub-processorPurposeLocation
Supabase, Inc.Database hosting, authenticationEuropa
Vercel Inc.Application hosting, static assetsEU / US (SCCs)
Mollie B.V.Payment processingEuropa
Anthropic PBCAI suggestions (no training on your data)US (SCCs + DPF)
Microsoft Azure Communication ServicesTransactional emailEuropa
Affiliate networks (Daisycon, Awin, TradeTracker)Click-tracking + commissionEU
Print.onePhysical cardsNL

We notify you at least 30 days in advance of any changes to this list, so you can object. Current list always available on request.

7. Security measures

We take appropriate measures to protect your data against loss, unauthorised access and alteration:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Row-level security on all user tables in the database
  • Two-factor authentication required for all staff
  • Principle of least privilege — only engineers who need it, with audit trail
  • Daily automated backups with 30-day retention
  • Annual penetration test and monthly dependency scan
  • Incident response procedure with defined contact point (dpa@attentico.nl)

8. International transfers

Personal data is processed within the EEA where possible. For sub-processors outside the EEA (currently Anthropic in the US) we base transfers on the European Commission's Standard Contractual Clauses (Decision 2021/914) and, where applicable, the EU-US Data Privacy Framework.

9. Liability

The liability provisions in our general terms apply in full to this DPA. For direct damages caused by Attentico's attributable breach, our liability is capped at the subscription fees you paid in the twelve (12) months preceding the incident, with a minimum of €500.

10. Governing law

Dutch law applies. Disputes are submitted to the competent court in The Hague, unless mandatory law provides otherwise.

Questions or need a signed version?

Email us at dpa@attentico.nl — we usually return a counter-signed PDF within the same working day.

    Data Processing Agreement (DPA) · Attentico