This data processing agreement forms part of the Terms of Use and applies for as long as Glimps processes personal data for the Customer.
Parties: the Customer who accepted the Terms of Use, as controller, and Glimps, Chamber of Commerce 94781745, Sint Lambertusweg 18, 5953 CJ Reuver, the Netherlands, as processor.
1. Instructions
1.1 Glimps processes personal data only on the Customer's instructions, for the purposes in Annex 1. The Terms of Use, this agreement and the settings the Customer chooses in the platform together constitute the complete instruction.
1.2 Glimps informs the Customer immediately if, in its view, an instruction conflicts with the GDPR.
1.3 Glimps does not process the data for its own purposes. User corrections are used only within that Customer's account. Learning across customers with Customer Data is not permitted. Only genuinely anonymised statistics may be used to operate and improve the Service.
2. Confidentiality
Everyone processing personal data under the authority of Glimps is bound by confidentiality.
3. Security
Glimps takes appropriate technical and organisational measures under Article 32 GDPR. The current measures are set out in Security Measures, Annex 3 to this agreement. Glimps may change those measures, provided the level of protection does not materially decrease.
4. Subprocessors
4.1 The Customer gives general authorisation for the subprocessors on the subprocessor list, Annex 2 to this agreement. The list in force at acceptance is thereby authorised.
4.2 Glimps publishes an addition or replacement on the subprocessor page. The Customer may subscribe to email notification of changes through [email protected]. The Customer may object to a new subprocessor in writing, with reasons. If the parties cannot resolve it, the Customer may disable the relevant function or terminate the agreement.
4.3 Glimps imposes on subprocessors obligations at least equivalent to this agreement, and remains responsible to the Customer for their performance.
5. Transfers outside the EEA
The processing location per subprocessor is stated on the subprocessor list. Where a party processes outside the EEA or may have access, Glimps uses a valid transfer mechanism: an adequacy decision, the EU-US Data Privacy Framework, or standard contractual clauses.
6. Assistance to the Customer
6.1 Glimps assists the Customer with data subject requests, with security, with breach notification duties, and with a DPIA or prior consultation.
6.2 If a data subject request reaches Glimps directly, Glimps forwards it to the Customer without delay. Glimps does not handle it independently.
6.3 Glimps charges for assistance beyond the standard functionality of the Service only after a quotation given in advance.
7. Personal data breaches
7.1 Glimps informs the Customer without undue delay after becoming aware of a breach affecting the Customer. The operational target is within 24 hours, and where reasonably possible no later than 48 hours. The first notification may be provisional and is supplemented as more becomes known.
7.2 Notification to the supervisory authority and to data subjects is the Customer's responsibility. Glimps does not notify on the Customer's behalf.
8. Audit
8.1 Glimps makes available, on request, the information needed to demonstrate compliance.
8.2 The Customer may, at most once per calendar year, at its own cost and with 30 days' notice, have an audit carried out during office hours and without disproportionate disruption. That frequency limit does not apply where an incident or a supervisory authority reasonably requires an additional audit. Findings are confidential.
8.3 Glimps holds no ISO 27001 or SOC 2 certification to refer to.
9. Deletion and return
9.1 The Customer may at any time request a full export of its exportable Customer Data and metadata through [email protected]. Glimps delivers this in a structured, commonly used and machine-readable format, within 30 calendar days and free of charge.
9.2 After the agreement ends, Glimps keeps the data for 90 days, so the Customer can export or reopen the account. After that, Glimps deletes Customer Data from production within 30 days. Copies in backups expire within a maximum of 30 days after that. The Customer may request a longer retention period in writing before the agreement ends.
9.3 Glimps retains longer where the law requires it, such as for its own billing administration.
9.4 The Customer remains responsible for its own statutory retention duties. Without a separate written archiving agreement, Glimps is not the Customer's statutory long-term archive.
10. Liability and term
10.1 The liability provisions of the Terms of Use apply in full to this agreement.
10.2 Provisions that by their nature continue, such as confidentiality, survive termination.
Annex 1: Overview of processing
Nature and purpose: automated processing of purchase invoices. Receipt through upload and email, reading, supplier recognition, proposals for coding and VAT, matching with purchase orders, approval workflows, posting into the Customer's accounting package, notifications and reporting.
Categories of data subjects:
- employees and representatives of the Customer;
- contacts and employees of the Customer's suppliers;
- sole traders and freelancers acting as suppliers;
- other individuals whose data appears in invoices or emails the Customer processes.
Categories of personal data:
- name, address and contact details, job titles and signatures on invoices;
- financial data: invoice amounts, IBAN, VAT numbers and payment references;
- email metadata from connected mailboxes: sender, subject, attachment names and classification;
- approval actions, comments and questions from users;
- the content of AI conversations, to the extent the user enters it.
Special categories of personal data are not intended. Because free text, emails and documents are processed, they may incidentally occur. The Customer avoids this unless a valid legal basis and an appropriate instruction exist.
Duration: for the term of the main agreement, and thereafter as set out in section 9.
Annex 2: Subprocessors
Annex 3: Technical and organisational measures
See Security Measures.
Questions about this document? [email protected]