Skip to legal content
Legal & Trust Center
Trust Center Contact IK Studios ↗
Legal Center

Trust & Security

Data Processing Agreement

For business customers whose use of our services involves us processing personal data on their behalf, here is the framework of our DPA.

Owner
IK Studios
Updated
June 28, 2026
Effective
June 28, 2026
Scope
Netherlands · EU / EEA

On this page

When a DPA appliesRolesOur commitments as processorInternational transfersRequesting a signed DPA

Back to Legal Center

Policy library

Overview

Trust CenterLegal FAQ

Privacy & Data

Privacy PolicyCookie PolicyGDPRCCPA (California)Data RetentionData DeletionPrivacy PreferencesCookie Settings

Terms & Use

Terms of ServiceLicense AgreementAcceptable UseSubscription TermsRefund Policy

Trust & Security

SecurityResponsible DisclosureSubprocessor ListThird-Party ServicesData Processing AgreementService Statussecurity.txt

Intellectual Property & Brand

Copyright PolicyCopyright NoticeTrademark PolicyBrand AssetsPress & MediaOpen Source Notices

Disclaimers & Liability

Website DisclaimerSoftware DisclaimerLimitation of Liability

Artificial Intelligence

AI Usage Policy

Accessibility

Accessibility Statement

Company

Contact & Legal InfoCommunity Guidelines

On this page

When a DPA appliesRolesOur commitments as processorInternational transfersRequesting a signed DPA

When a DPA applies

Most of the time, IK Studios is the controller of the personal data it handles. A Data Processing Agreement (DPA) is relevant where you are a controller and we process personal data on your behalf as a processor — for example under certain business arrangements. This page summarises our DPA framework; a signed DPA governs once in place.

Roles

Under a DPA, you are the controller and decide the purposes and means of processing; IK Studios is the processor and acts on your documented instructions. We remain the controller for data we process for our own purposes, such as billing and security.

Our commitments as processor

Our standard DPA commits us to:

  • Process personal data only on your documented instructions.
  • Ensure people authorised to process it are bound by confidentiality.
  • Implement appropriate technical and organisational security measures.
  • Engage subprocessors only under equivalent obligations, with notice of changes — see the Subprocessor List.
  • Assist you with data-subject requests and with your own security and DPIA duties.
  • Notify you without undue delay of a personal-data breach affecting your data.
  • Delete or return personal data at the end of the engagement, subject to legal retention.
  • Make available information needed to demonstrate compliance and allow for audits as the GDPR requires.

International transfers

Where processing involves transfers outside the EEA, our DPA incorporates Standard Contractual Clauses and appropriate safeguards.

Requesting a signed DPA

Email support@ikstudios.nl with your company details and we will provide our standard DPA for signature. For Vault One enterprise arrangements, see also the Vault One DPA.

Contact & notices

Questions about these documents, your privacy rights, a security report, or a business agreement — we read every message and route it to the right person.

General, privacy & security
support@ikstudios.nl
Business & billing
sales@ikstudios.nl
Product feedback
feedback@ikstudios.nl
Full contact page
Contact & Legal Information
Legal CenterPrivacyTermsCookiesSecurityTrust CenterContactIK StudiosVault One

IK Studios policies are written to be read — plain language first, with the detail behind it. We keep them aligned to what we actually build.

Last updated June 28, 2026. Questions: support@ikstudios.nl. These documents apply to IK Studios and its websites; product-specific terms for Vault One live in the Vault One Trust Center.

© 2026 IK Studios. An independent software studio.