Trainiq
PlatformWho it is forQuinn AITrainiq ConnectPricingBlog 085 071 1114 Free demo Nederlands

Data processing agreement

Last updated: 11 May 2026

This English version is provided for convenience. The Dutch version is the binding one.

As a training provider you process personal data of your participants. As soon as you use third-party software for that (such as Trainiq), the GDPR (article 28) requires you to conclude a data processing agreement (DPA) with that supplier. Many SaaS suppliers have you sign a separate document for this. Trainiq works differently: the DPA is built into our terms and conditions.

The moment you accept our terms and conditions, the data processing agreement is concluded. No extra signature, no separate PDF, no yearly renegotiation.

With Trainiq you meet the GDPR automatically

The General Data Protection Regulation obliges you, as controller, to lay down clear arrangements for every processor (such as a SaaS platform): what data is processed, on which legal basis, where it is stored, who has access, how long it is kept and what happens in the event of a data breach.

We have put all of those arrangements into articles 20 to 29 of our terms and conditions. Together those ten articles form a full DPA as article 28 GDPR requires.

What is in the data processing agreement?

The ten articles that together form the DPA:

  • Article 20 — Personal data: which categories of data are processed
  • Article 21 — Purposes of processing: what for, and what not for
  • Article 22 — Obligations of the processor: only on instruction, cooperation with DPIAs
  • Article 23 — Transfers: sub-processors, EEA only
  • Article 24 — Division of responsibility: you are the controller, Trainiq is the processor
  • Article 25 — Security: encryption, magic link, access control, backups
  • Article 26 — Duty to report: notification of a data breach to you within 48 hours
  • Article 27 — Handling requests from data subjects: you remain the first point of contact, we facilitate
  • Article 28 — Secrecy and confidentiality: also after termination
  • Article 29 — Audit: one audit per year, certifications may replace audits

Read the full DPA →

Your data is well protected

We have taken appropriate technical and organisational measures: everything encrypted in transit (TLS 1.2+) and at rest, passwordless magic-link authentication, role-based access control, an audit log of administrative actions, and daily tested backups. The full security policy is at trainiq.nl/en/beveiliging.

Every sub-processor we work with (hosting, e-mail, payments, accounting, AI) is established within the European Economic Area. The current overview, including location, certifications and data categories, is at trainiq.nl/en/subverwerkers.

Frequently asked questions

Why no separate agreement?

Legally, a built-in DPA is just as binding as a separate one. The advantage: one document, one moment of change, no version mismatch between your copy and ours. For you it means less paperwork; for us it means we don't have to organise a signing round for every new training provider.

Am I still the controller?

Yes. For the participant data you put into Trainiq, you are the controller: you decide why you collect that data, you are the point of contact for your participants, and you are obliged to inform your participants through your own privacy statement. Trainiq is the processor for that data, on your instruction.

What else do you do for my GDPR compliance?

Nothing outside the scope of the platform. We make sure our processing complies with the GDPR: encryption, access control, EU-only data, a data breach procedure, audit rights. What you do around your own privacy statement, your retention policy towards participants, training your own staff, or your wider GDPR compliance (for example towards suppliers other than Trainiq) is your responsibility. We can't promise anything there and we are not liable for it.

My large client insists on a separately signed DPA. Is that possible?

For large client companies (for example staffing agencies, multinationals, government bodies) we conclude a bespoke DPA on request in exceptional cases. Send an e-mail to info@trainiq.nl with the scope and we will get in touch. In practice such bespoke DPAs differ little, if at all, from the built-in version above.

What if you want to add a new sub-processor?

We announce changes to our list of sub-processors at least 30 days before they go live, on trainiq.nl/en/subverwerkers and by e-mail to our customers. If you have a reasoned objection to a new sub-processor, you can tell us by e-mail; as a last resort that is a ground to terminate the Agreement with immediate effect. See article 23 of the terms and conditions.

How do I report a data breach?

Do you suspect a data breach that affects Trainiq? E-mail info@trainiq.nl as soon as possible with "DATA BREACH" in the subject line. We get in touch within 4 hours and start the procedure described in article 26 (notification to you within 48 hours, with all the information you need to inform the Dutch Data Protection Authority within 72 hours).

Questions?

Not sure whether the built-in DPA is enough for your situation? E-mail info@trainiq.nl or call +31 85 071 1114. We are happy to help, also if it turns out you need a separate version.

Trainiq

The platform for training providers

PlatformAll featuresPortalsPricingTrainiq ConnectQuinn
Who it is forBHV training providersVCA providersCode 95 trainersHealthcare trainingDog training schoolsCourse administration
SupportBlogLegalPrivacySecurityContact

© 2026 Trainiq B.V. · Einsteinlaan 28, 2289 CC Rijswijk, the Netherlands · Chamber of Commerce 42053044 · +31 85 071 1114