Legal
Data processing agreement
Last updated July 1, 2026
Data Processing Agreement Spectacle B.V.
THE UNDERSIGNED
This Data Processing Agreement (“DPA”) forms an integral part of the Agreement between Spectacle B.V. (“Processor”) and the Customer (as defined in the Agreement) (“Controller”) and applies automatically to any Processing of Personal Data by Processor on behalf of Controller under the Agreement. It is effective as of the Effective Date of the Agreement or the date both parties execute this DPA, whichever is earlier.
Hereafter referred to collectively as: Parties.
CONSIDERING THAT:
- Processor provides (online) services for Controller, whereby Processor processes personal data — Personal Data that befall Controller — as referred to in the General Data Protection Regulation (“Regulation”) for, and on behalf of Controller;
- Parties wish to make agreements on this in the form of a Data Processing Agreement;
- Processor can, during the implementation of an agreement with Controller, be classified as Processor within the meaning of article 4 sub 8 of the Regulation;
- Controller will be classified as Controller within the meaning of article 4 sub 8 of the Regulation;
- When in this Data Processing Agreement mentioning is made of personal data, it refers here to personal data within the meaning of article 4 sub 1 of the Regulation;
- Processor is willing to meet its obligation regarding security and other aspects of the Regulation, as far as this is within its control;
- The Regulation imposes the Controller should ensure that the Processor provides sufficient and “state of the art” guarantees, with reference to technical and organizational security measures regarding the processing that must be carried out;
- Next to this, the Regulation imposes the Controller to ensure the compliance with those measures;
- Parties, in view of the requirements in article 28 section 3 of the Regulation, wish to put their rights and obligations in writing through this Data Processing Agreement.
- Next to the Regulation, certain customers may be subject to the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). Parties therefore agree that the Processor will act as a Service Provider under the CCPA when applicable.
- This Data Processing Agreement forms an integral and mandatory part of the Agreement between Processor and Controller and applies to all subscription plans, regardless of the selected tier or pricing level. The Controller does not need to separately execute this DPA; it applies automatically upon acceptance of the Terms of Service.
HAVE AGREED AS FOLLOWS
Article 1. DEFINITIONS
1.1 Personal data: any information relating to or traceable to an identified or identifiable natural person (the “Data Subject”);
1.2 Data: all other information (data) that are not Personal Data;
1.3 Data Subject: the person to whom the Personal Data relate. In the case of a child below the age of 16, the Data Subject refers to the child’s legal representative(s);
1.4 Data Processing Agreement: the agreement between Controller and Processor;
1.5 Agreement: Agreement between Processor and Controller regarding the service(s) delivered by the Processor to the Controller;
1.6 Processing: an operation or a set of operations relating to Personal Data or a set of Personal Data, either or not carried out through automated procedures, such as collection, recording, organization, structuring, storage, updating or modifying, requesting, consulting, usage, dissemination by means of transmission, distribution or making it otherwise available, alignment or combination, protection, erasure or destruction of data;
1.7 Controller: a natural or legal person, a public authority, a service or any other organ that — alone or jointly with others — determines the aims and means for the processing of Personal Data; when the aims and means of this processing are determined by Union or Member State Law, it may provide who the controller is or it may designate the specific criteria for his nomination (“Controller”);
1.8 Processor: the entity which processes Personal Data on behalf of the Controller;
1.9 European Economic Area: all countries of the European Union, Liechtenstein, Norway and Iceland;
1.10 Data breach: a security breach that accidentally or unlawfully leads to the destruction, the loss, the altering or the unauthorized disclosure of or the unauthorized access to the forwarded, saved or otherwise processed data and/or Personal Data;
1.11 Supervisory authority: an independent public authority responsible for supervising the compliance with the law and regulations regarding the processing of Personal Data. In the Netherlands, this is the Personal Data Authority;
1.12 Sub-Processor: A professional party who is brought in by Processor to take on (part of) the Processing.
Article 2. PURPOSES OF PROCESSING
1. Processor agrees, according to the conditions set out in this Data Processing Agreement, by order of Controller, to process Personal Data. Processing will solely take place in the context of the Data Processing Agreement and those objectives as mentioned in paragraph 2.
2. The processing’s commercial objective is the provision of marketing attribution and optimization services, with the aim of helping the Controller identify effective marketing channels, optimize advertising spend, and improve customer acquisition and retention. A detailed plan of the authorized processing of the Personal Data is defined in Appendix A.
3. The Personal Data that are to be processed are listed in Appendix A.
4. Processor will not process the Personal Data for any purpose other than determined by the Controller. Controller will inform Processor of the processing objectives, where this has not already been mentioned in this Data Processing Agreement.
5. The Processor has no authority over the aims and the means for the processing of Personal Data. The Processor will not take any decisions independently regarding the receipt and use of the Personal Data, disclosure to third parties and the duration of the storage of Personal Data.
6. Controller is solely responsible for determining the retention periods applicable to Personal Data processed under the Agreement and for instructing Processor regarding any deletion, return, export, or retention requirements, except to the extent mandatory retention periods apply under applicable law.
7 During the term of the Agreement, Processor shall retain Personal Data in accordance with the Agreement, this DPA, Controller’s documented instructions, and applicable law.
Article 3. OBLIGATIONS PROCESSOR
1. With regard to the processing operations mentioned in article 2, the Processor will ensure compliance with the terms that, on the basis of the Regulation, are prescribed for the processing of Personal Data.
2. Processor will, upon his first request, inform Controller about the measures it has introduced regarding its obligations covered under this Data Processing Agreement.
3. The Processor’s commitments that come forth from this Data Processing Agreement also apply to any person who processes Personal Data under the authority of Processor.
4. The processing of Personal Data by Processor will never entail that Processor’s databases will be enriched with personal data derived from the data sets of Controller.
5. Processor solely acts as processor by order of and by means of concrete instructions and only processes Personal Data by order of Controller.
6. Notwithstanding Article 3.4, the Controller grants the Processor permission to use aggregated, pseudonymised, or anonymised data derived from the processing activities under this Data Processing Agreement for the purpose of improving the Services, generating benchmarks, and conducting internal analytics, provided that:
(a) such data cannot reasonably be used to identify individual data subjects;
(b) the Processor does not disclose such data to third parties in a form that could identify the Controller or its data subjects; and
(c) the processing is carried out in accordance with the Regulation and any applicable data protection laws.
Article 4. TRANSFER OF PERSONAL DATA
1. Processor may process Personal Data in countries within the European Economic Area. Transfer to countries outside of the European Union is permitted with prior written approval of Controller. The storage of Personal Data is also included.
2. Processor will notify Controller which country or countries are involved in case of transfer or storage in countries outside the European Economic Area. The Personal Data may only be processed in a safe third country as far as this is permitted by the Resolution (a country which offers an adequate level of protection).
3. It is recorded in Appendix A of this Data Processing Agreement exactly which Personal Data Processor will process and for which processing purposes.
Article 5. DISTRIBUTION OF RESPONSIBILITY
1. The authorized processing operations will be carried out within an automated environment, but may from time to time be processed manually.
2. Processor is solely responsible for the processing of Personal Data covered under this Data Processing Agreement, in accordance with the instructions of Controller and under the explicit (final) responsibility of Controller. Processor is not responsible for all other processing operations of Personal Data, always including but not limited to the collection of Personal Data by the Controller, processing operations for objectives that were not notified to the Processor by the Controller, processing operations for third parties and/or other objects. The responsibility for these processing operations solely lies with Controller.
Article 6. INVOLVING THIRD PARTIES AND SUB-PROCESSORS
- Controller hereby grants Processor general written authorization to engage third parties or Sub-Processors in the performance of the Agreement. The Sub-Processors engaged at the date of this Data Processing Agreement are listed in Appendix B.
- Processor shall inform Controller in writing of any intended addition or replacement of a Sub-Processor, including the identity of the Sub-Processor, the categories of personal data processed, and the location of processing. Controller may object to such addition or replacement on reasonable, duly substantiated grounds within fourteen (14) days of receipt of the notification. If Controller does not object within this period, the addition or replacement shall be deemed approved and Processor may engage the Sub-Processor.
- If Controller objects within the period set out in paragraph 2, the Parties shall enter into good-faith consultation to find a workable solution. If the Parties are unable to reach agreement within thirty (30) days of the objection, Processor may continue to engage the Sub-Processor and Controller may terminate the part of the Agreement affected by the change without penalty as its sole and exclusive remedy.
- Processor shall enter into a written agreement with each Sub-Processor imposing data protection obligations no less protective than those set out in this Data Processing Agreement, in accordance with Article 28(4) GDPR. Processor shall monitor each Sub-Processor's compliance with these obligations and remains fully liable to Controller for any acts or omissions of the Sub-Processor in connection with the processing of personal data under this Agreement.
Article 7. SECURITY AND CONFIDENTIALITY
1. Processor shall make every effort to take sufficient technical and organizational measures regarding the processing of Personal Data that must be carried out, against loss or any other form of unlawful processing (such as unauthorized cognizance, violation, modification or disclosure of Personal Data). This security shall at least consist of state of the art technical and organizational measures. An overview of these measures and the policy thereon is defined in Appendix C.
2. Processor shall make efforts in order to ensure the security meets a level which, taking into account the state of the art, the sensitivity of the Personal Data concerned, and the expenses associated with making the security arrangements, is not unreasonable.
3. Controller only makes Personal Data available to Processor for processing operations, when it has assured itself that the required security measures have been taken. Processor is responsible for compliance with the measures agreed upon by Parties.
4. In accordance with the Regulation, Processor is legally obliged to a duty of confidentiality. Processor is obliged to treat all (Personal) Data received as confidential.
5. Processor obliges its (past) employees and/or subcontractors to a duty of confidentiality with regard to all Personal Data which they obtain with regard to the Agreement.
6. If Processor receives a request or decree of a Dutch or foreign compliance officer or an investigation authority, an authority that deals with criminal proceedings or a national safety authority, asking to provide (access to) Personal Data, then the Processor will immediately inform the Controller. When examining the request, the Processor will observe all instructions of the Person Responsible and render all the reasonably necessary cooperation.
Article 8. DUTY TO NOTIFY DATA BREACH
1. In case of a Data breach, Processor will exert itself to the best of its abilities to, without undue delay and within 72 hours after detection, inform Controller about this. Processor shall exert itself the best of its abilities to ensure that the provided information is as complete, correct and accurate as possible. The duty to notify applies regardless of the impact of the Data breach.
2. When laws and/or regulations so require, Processor will collaborate by informing the in this case relevant authorities and possible parties concerned.
3. The Duty to notify concerns in any case the reporting of the fact that a Data breach has occurred, as well as:
- What the (alleged) cause is of the Data breach;
- What the (as yet known and/or anticipated) consequence is of the Data breach;
- What the (proposed) solution is for the Data breach;
- What measures have already been taken.
Article 9. PROCESSING REQUESTS OF PARTIES CONCERNED
1. In the event that a Data Subject submits a request for inspection, as referred to in article 15 of the Regulation, or improvement, addition, modification or screening, as referred to in article 16 and following of the Regulation, to the Processor; then the Processor will forward this request to the Controller, who will then deal with the request.
Article 10. AUDIT
1. Controller has the right to have audits carried out by an independent ICT expert, who is observing confidentiality, to check compliance with all points stipulated in this Data Processing Agreement.
2. This audit will solely take place after Controller has requested similar audit reports available at the Processor’s, has evaluated these and has given reasonable arguments to justify the audit initiated by the Controller. Such an audit is justified if the similar audit reports, made available by the Processor, give either insufficient or inconclusive information regarding the Processor’s compliance with the Data Processing Agreement. The audit, initiated by Controller, will take place two weeks after prior notice from Controller.
3. Processor will cooperate with the audit and will provide all information reasonably relevant for the audit, including supporting data such as system logs, as well as employees, as fast as possible and within a reasonable period, in which case a period of two weeks is reasonable unless an urgent interest opposes this.
4. The findings following the executed audit will be evaluated by Parties in mutual consultation and, as a result of this, will or will not be implemented by one of the Parties or jointly by both Parties.
5. The expenses for the audit will be borne by Controller, provided that the expenses for the hired third party will always be borne by Controller.
Article 11. DURATION AND TERMINATION
1. This Data Processing Agreement has been entered into for the duration as specified in the Agreement between Parties and, failing this, in any case for the duration of the collaboration. In the event that the provision of services by the Processor to Controller should (still) continue, this Data Processing Agreement will continue.
2. The Data Processing Agreement cannot be terminated mid-term.
3. Upon termination of this Data Processing Agreement, the provisions of articles 3, 8, 9 and 12 of this Data Processing Agreement will remain fully applicable.
4. Processor is allowed to modify this Data Processing Agreement and to communicate the changes to this Data Processing Agreement to the Controller.
5 Upon termination or expiry of the Agreement, Controller may, during a period of one thirty (30) days following such termination or expiry, request in writing the export, return, or deletion of Personal Data processed by Processor on Controller’s behalf.
6 Unless Controller requests earlier deletion in writing, Processor may retain the Personal Data for up to one hundred eighty (180) days following termination or expiry of the Agreement solely for the purposes of enabling export, return, transition assistance, backup cycling, security, fraud prevention, dispute management, and compliance with applicable law. During such period, Processor shall continue to protect the Personal Data in accordance with this DPA and shall not Process such Personal Data for any other purpose.
7 Following the expiry of the 180-day period referred to in Article 11.5, Processor shall delete or render inaccessible the Personal Data from its active systems within a reasonable period, unless Union law, Member State law, or other applicable law requires continued retention.
8 Controller acknowledges that it is solely responsible for requesting export or return of any Personal Data it wishes to retain before expiry of the 180-day period.
Article 12. LIABILITY
- The liability provisions set out in the Terms of Service (including the exclusion of indirect damages, the cap on direct damages, and the mutual application thereof) apply equally to this Data Processing Agreement.
- To the extent that any claim arises from a breach of this Data Processing Agreement, the aggregate liability of the Processor shall in no event exceed the cap on direct damages set out in the Terms of Service.
- Nothing in this Article shall limit the Processor's liability for intentional misconduct (opzet) or gross negligence (grove schuld).
Article 13. CCPA / CPRA Service Provider Obligations
1. When the Controller is subject to the CCPA/CPRA, the Processor acts as a Service Provider and processes Personal Data solely to provide the services under the Agreement.
2. The Processor does not sell or share Personal Data, nor retain, use or disclose Personal Data for any purpose other than providing the services.
3. The Processor does not combine Personal Data received from the Controller with Personal Data from other clients, except as permitted for security or to provide the services.
4. The Processor assists the Controller with CCPA consumer rights requests as reasonably required.
Article 14. OTHER PROVISIONS
1. Solely Dutch law is applicable to the Data Processing Agreement and its implementation.
2. The obligations arising from this Data Processing Agreement take effect after Controller has safely delivered the Personal Data to the Processor.
3. All disputes, which might arise between Parties with regard to the Data Processing Agreement, will be put before the competent court of the Court in Amsterdam.
4. If the data-protection laws should change, Parties will cooperate to modify this Data Processing Agreement in order to (continue) to stay in line with prevailing legislation.
5 This DPA constitutes the parties’ complete agreement with respect to Processing of Personal Data by Processor on behalf of Controller under the Agreement and supersedes any conflicting or additional data processing terms proposed by Controller, unless expressly agreed in writing and signed by both parties.
Appendix A
Nature and purposes of processing
Spectacle is a provider of cloud-based marketing attribution software, headquartered in the Netherlands. These services consist primarily of tracking and attributing customer conversions across multiple marketing touchpoints to provide insights into campaign effectiveness and customer acquisition patterns. Spectacle provides analytics and reporting capabilities to help customers optimize their marketing spend and improve customer acquisition quality. The platform may also facilitate campaign optimization activities as agreed between the parties.
Otherwise, the data processing will involve any such processing that is necessary for the purposes set out in the Agreement, the DPA, or as otherwise agreed between the parties. Where applicable, Spectacle will process Personal Data as a Service Provider under the CCPA/CPRA.
Categories of data subjects
The personal data transferred concerns primarily the Customer’s website visitors, leads, and customers.
Categories of data
The personal data transferred concern the following categories of data for the data subjects:
- Website visitor data including IP addresses, device identifiers, browser information, and behavioral data
- Customer contact information such as email addresses, names, and company information when provided by the Customer
- Marketing campaign interaction data including ad clicks, form submissions, and conversion events
- Any other personal data that the Customer chooses to send to Spectacle through integrations, APIs, tracking implementations, or any other means
The personal data transferred to Spectacle for processing is determined and controlled by the Customer in its sole discretion. As such, Spectacle has no control over the volume and sensitivity of personal data processed through its service by the Customer.
The Spectacle platform, APIs, databases, and other services are hosted in AWS’s data centers in Ireland.
Special categories of data
Spectacle does not intentionally collect or process any special categories of data in the provision of its service.
Under the Agreement, the Customer agrees not to provide special categories of data to Spectacle at any time.
Appendix B
Sub-processors
Amazon Web Services Amazon Web Services (AWS) is the main hosting provider of the Spectacle platform.
ClickHouse (cloud) ClickHouse is the main analytics database that powers the Spectacle platform.
Snitcher B.V.
Snitcher B.V. provides website visitor identification services (marketed as "Lens" within the Spectacle platform). Website visitor identification is an add-on that is operated and offered separately and is therefor strictly a sub-processor when services are enabled by the customer.
Snitcher processes visitor IP addresses and related metadata to identify the companies visiting the Customer's website. Snitcher acts as a sub-processor under this DPA. Data is processed and stored within the European Economic Area.
All Sub-processors are bound by written terms consistent with GDPR and, where applicable, CCPA/CPRA Service Provider obligations.
RB2B, Inc. (operating as Retention.com)
RB2B, Inc. provides person-level website visitor identification services for US-based visitors (offered as part of the "Lens" functionality within the Spectacle platform). Person-level visitor identification is an add-on that is operated and offered separately and is therefore strictly a sub-processor when services are enabled by the Customer.
RB2B processes visitor IP addresses, device and browser metadata, and on-site behavioural signals to identify individual visitors and return identifiers such as name, professional profile URL, and business email address. By design, RB2B applies IP ringfencing so that person-level resolution is performed only for traffic originating from US IP addresses; non-US traffic is not resolved to the person level. RB2B acts as a sub-processor under this DPA, on the terms set out in its Data Protection Addendum (available at rb2b.com/data-protection-addendum-dpa).
Data is processed and stored in the United States. To the extent any personal data of EEA or UK data subjects is transferred to RB2B, such transfers are governed by the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), together with supplementary measures as required under applicable data protection law.
Appendix C
Technical and organizational measures
1. Measures to guarantee confidentiality
1.1. Physical access control Measures to prevent unauthorized individuals from gaining physical access to IT and data processing systems for processing personal data and to confidential files and storage media:
- Handled by Spectacle’s hosting provider AWS. You can read more about AWS security practices and compliance here: https://aws.amazon.com/security/
1.2. Logical access control Measures to prevent protected data from being processed or used by unauthorized persons:
- User management with strict, granular access rights
- Regular access rights audits
- Employee training
1.3. Data access control Measures which guarantee that the person authorized to use the data processing processes can exclusively access their personal data which are subject to their access authorization so that data cannot be read, copied, changed, stored or removed during the processing without authorization:
- User management with strict, granular access rights
- Regular access rights audits
- Employee training
1.4. Separation instruction Measures that reassure that data collected for different reasons is processed separately and therefore being separated from other data and systems in order to guarantee that an unplanned processing of these data for other reasons is impossible:
- Separation of development, test and production systems.
2. Measures to secure integrity
2.1. Data transfer control Measures which guarantee that personal data cannot be read, copied, changed or removed during the electronic transmission or during their transport or storage on data carriers without authorization as well as measures ensuring checking and determination of the locations a transmission of personal data is designated:
- Audit logs
- Encrypted transmissions
2.2. Input control Measures which guarantee that it can be subsequently checked and determined whether and by whom personal data have been entered, changed in or removed from the data processing systems:
- Database auditing logs
3. Measures to ensure availability and capacity
3.1. Availability control Measures to ensure that personal data are protected against accidental destruction or loss:
- Continuous replication
- Daily snapshots
- Redundant design of critical components