Last updated: 27 July 2026
When Heerden & Co works with a client's marketing data, it may process personal data about that client's own customers or staff. In those cases the client is the controller and Heerden & Co is the processor. This page sets out the standard terms for that processing under Article 28 GDPR, together with the sub-processor list.
The Processor is Heerden & Co, trade name of ABSVH Investments B.V. (KvK 76998568), Box C6827, Keurenplein 41, 1069 CD Amsterdam, Netherlands. The Controller is the client that engages Heerden & Co. The Controller determines the purposes and means of the processing; the Processor acts only on the Controller's documented instructions.
The Processor processes personal data only to the extent needed to deliver the engagement agreed with the Controller — reviewing marketing performance, analysing data end to end, diagnosing the constraint, and designing and installing the marketing system. Processing lasts for the duration of the engagement.
Depending on the engagement, the personal data processed may include:
The Processor does not process special categories of personal data unless expressly agreed in writing.
The Processor applies measures appropriate to the risk, including: encrypted connections (HTTPS/TLS), access on a need-to-know basis, strong authentication, use of reputable providers with their own certifications, and minimising the personal data accessed to what the engagement requires.
The Controller gives general authorisation for the Processor to use the sub-processors below. The Processor imposes data-protection obligations on each sub-processor equivalent to those in this DPA, and remains liable for their performance. The Processor will inform the Controller of any intended change and give the Controller the chance to object.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Ireland Ltd | Email, calendar and file storage (Google Workspace); analytics tooling used during engagements | EU / US |
| Vercel Inc. | Website hosting | EU / US |
| Web3Forms | Contact / fit-call form processing | EU / US |
| Mollie B.V. | Payment processing | Netherlands (EU) |
Additional tools may be introduced for a specific engagement; where they process the Controller's personal data, they will be added to this list and notified to the Controller.
Where a sub-processor processes personal data outside the European Economic Area, the transfer is covered by the EU Standard Contractual Clauses and/or the sub-processor's certification under the EU–US Data Privacy Framework.
The Processor assists the Controller, as far as reasonably possible, with responding to data-subject requests and with the Controller's obligations on security, breach notification, and data-protection impact assessments. The Processor notifies the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data.
On termination of the engagement, the Processor returns or deletes the Controller's personal data at the Controller's choice, unless a legal obligation requires retention (for example, invoicing records kept for the statutory term).
The Processor makes available the information reasonably needed to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable notice and confidentiality.
This DPA is governed by Dutch law. Disputes are submitted to the competent court in Haarlem (Rechtbank Noord-Holland).
← Back to the homepage