Order Form and Agreement
Version 2026-07-26-v3. Engage Data Consulting BV (Engage Compliance), KvK 82538638, Amsterdam.
The Order Form (Part 1) records the Customer, the Services Package, the Fees, and the Start Date, and is completed at checkout. The Service Level Agreement, the Services Agreement, and the Data Processing Agreement below apply in full.
Engage Data Consulting BV ("Engage")
Order Form and Agreement
This document comprises the Order Form (Part 1), the Service Level Agreement (Part 2), the Services Agreement (Part 3), and the Data Processing Agreement (Annex A). Together they form the entire agreement between the parties.
Part 1: Order Form
Custom Terms
Where the Services Package is Enterprise, or where the Customer and Engage agree any variation to the standard package (including the Initial Fee, the Ongoing Fees, the Included Hours, or the scope of Services), those variations are set out below. Custom Terms prevail over the Service Level Agreement and the Services Agreement to the extent of any conflict. If this section is left blank, the standard package applies without variation.
Fee and Payment Details
Initial Fees are due upon signing. Ongoing Fees are invoiced monthly in respect of each prior month and are due within 30 days of the invoice date. Where the Customer pays by card or direct debit under a subscription arranged by Engage, Fees are collected automatically in accordance with that subscription and no separate payment is required.
All Fees are stated exclusive of VAT and are payable in the Currency specified in the Order Form.
Where payment is made by bank transfer, Fees are to be paid to:
Name: Engage Data Consulting BV
IBAN: NL31INGB0006945923
Acceptance
By signing this Order Form, or by accepting these terms electronically at online checkout, the Customer agrees to this Order Form, the Service Level Agreement, the Services Agreement, and the Data Processing Agreement at Annex A. Both methods of acceptance are equally binding and have the same effect.
Part 2: Service Level Agreement
The following sets out what will be provided to the Customer, as aligned to the Services Package specified in the Order Form. These details apply in conjunction with the Services Agreement. "From" prices are the standard starting Fees for each package; the Fees that apply to the Customer are those stated in the Order Form.
Privacy Advisory
- Email Support (up to 1 Customer contact) [1]
- Risk and Oversight Committee (up to 4 times annually) [2]
- Audit (ongoing) [2]
- Data Protection Framework [3]
Privacy Advisory does not include a named DPO.
DPO Foundation
Same as Privacy Advisory, with the following additions:
- Named DPO [4]
- Additional Email Support (up to 3 Customer contacts)
- Breach support [5]
- Documentation Package (Standard) [6]
DPO Partner
Same as DPO Foundation, with the following additions:
- Additional Email Support (up to 5 Customer contacts)
- Office Hours Meetings (up to 1 per month)
- Data Protection Training (if needed)
- Google Workspace, Microsoft 365 and Slack support
DPO Complete
Same as DPO Partner, with the following additions:
- Full Email Support (all Customer staff)
- Additional Office Hours Meetings (up to 2 per month)
- Additional Audit (up to 2 per year in total)
- Advanced Breach support (meeting based, as needed) [7]
- Functional and Custom Data Protection Training (if needed)
- Documentation Package (Advanced) [8]
Enterprise
As set out in the Order Form and any Custom Terms.
Assessments and Training
Data protection impact assessments (DPIAs), transfer impact assessments (TIAs), and privacy training are scoped by package. On Privacy Advisory and DPO Foundation they are charged at client rates: DPIA EUR 1,000; TIA EUR 750; training EUR 750 per session. On DPO Partner and DPO Complete, assessments are included in the engagement scope and these add-on rates do not apply. A Customer that is not on a Services Package may commission the standalone DPIA service, priced per assessment from EUR 2,500.
Notes
[1] A 36 hour SLA applies for resolution, and 4 hours for confirmation of receipt, for most email queries. Due diligence requests have a higher SLA at 72 hours.
[2] The meeting requires senior leaders from the Customer to attend.
[3] The Audit and the Framework rely on the Customer providing sufficient information to Engage. Once sufficient information is provided, the SLA to complete or update the Framework is 7 days.
[4] Engage provides a named DPO, whose contact details are notified to the relevant supervisory authority by the Customer. The named DPO liaises with regulators and data subjects as needed, with the exception of data subject rights fulfilment, which is carried out by the Customer.
[5] Breach support includes Customer risk calculation support for privacy incidents and breach communications templates.
[6] Package policies and processes require Customer review, revision and implementation. Engage offers basic revision and support toward document finalisation. The package is provided as is. New policies will be added at no cost by Engage as needed by regulations.
[7] No additional charges apply for breach support which occurs outside working hours.
[8] The package includes additional policies.
A one-time onboarding fee applies to each Services Package and is due on signing: Privacy Advisory EUR 500; DPO Foundation EUR 1,000; DPO Partner EUR 1,500; DPO Complete EUR 2,500. Enterprise onboarding is as set out in the Order Form. The onboarding fee is waived where the Customer is billed annually.
Office Hours
Working hours for Engage are Monday through Thursday from 1000 to 1800 (Netherlands time). The office is closed on Fridays and on all national Dutch holidays. SLA timelines apply during working hours only.
Part 3: Services Agreement
This Services Agreement (the "Agreement") is between Engage Data Consulting BV ("Engage") and the Customer, and takes effect on the Start Date set out in the Order Form.
1. Services
Engage agrees to provide the services (the "Services") to the Customer as described in the Service Level Agreement, through Engage employees and service providers.
In order for Engage to provide the Customer with the Services, the Customer must provide certain contextual information and documentation in a timely, accurate, and truthful manner. If the Customer does not provide these, Engage is not liable for any damages to the Customer, financial or otherwise, whether or not relating to this Agreement.
The following are excluded from the Services, irrespective of the Services Package: insurances, translation services, litigation or investigation counsel, and breach forensics.
Engage does not act as the Customer's Article 27 EU Representative for so long as Engage acts as the Customer's DPO, consistent with EDPB Guidelines 3/2018.
2. Term and Termination
This Agreement lasts for the duration of the "Term", which begins on the Start Date set out in the Order Form and continues in perpetuity unless terminated by the Customer or Engage.
Either party may terminate this Agreement on 3 months written notice. The 3 month notice period begins on the first day of the month following the month in which notice is given.
Where Fees are collected by subscription, the subscription continues for the duration of the notice period and Fees remain payable for that period.
3. Responsibilities of the Customer
The Customer is solely responsible for any fines, penalties, damages, costs, attorney fees, investigative or litigation costs, or any other costs that may be incurred as a result of the Customer's processing of personal data, non-compliance with applicable regulations, or security breaches.
The Customer gives Engage timely access to the information and personnel necessary for the Services, and remains responsible for its own decisions and for implementing the advice given. Engage maintains professional indemnity and cyber insurance appropriate to the Services.
Where Engage acts as the named DPO for the Customer, the Customer must ensure that the DPO:
- is involved in, and provided with necessary and timely information regarding, the processing of personal data, especially any information reasonably requested by the DPO;
- does not receive any instructions regarding the exercise of the tasks associated with the Services inconsistent with GDPR Article 38(3);
- is permitted to report directly to the highest management level of the Customer, consistent with GDPR Article 38(3); and
- is notified of, and receives the Customer's cooperation on, any data protection impact assessments as needed, and of any known or suspected breach, or unauthorised or suspected unauthorised access to any personal data, or any other breach of security likely to lead to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to personal data (a "Security Breach"). For clarity, breach forensics and breach notification services are excluded from this Agreement unless otherwise agreed in writing.
The Customer is responsible for notifying the relevant supervisory authority of the named DPO's contact details and for publishing those details as required by GDPR Article 37(7). Engage will provide the Customer with the details required to do so.
4. Compensation
Fees. The Customer shall pay Engage the Fees set out in the Order Form. All Fees are non-refundable.
Package fit. Pricing is based on the information the Customer provides about its organization, data processing, and risk profile, including in any assessment or questionnaire completed before the Order Form. Where that information proves materially inaccurate or incomplete, Engage may move the Customer to the correct package on its published price list on 30 days written notice. Fees already paid are not refundable.
Initial Fees. A one-time onboarding fee applies to each Services Package and is due upon signing: Privacy Advisory EUR 500, DPO Foundation EUR 1,000, DPO Partner EUR 1,500, and DPO Complete EUR 2,500. Enterprise onboarding is as set out in the Order Form. The onboarding fee is waived where the Customer is billed annually. The Initial Fee payable by the Customer is stated in the Order Form.
Included Hours. Each Services Package includes a number of hours per month, set out in the Order Form and the Service Level Agreement. The Included Hours are a fair use ceiling on the advisory time a package typically needs, not an hourly entitlement the Customer purchases. The Fee buys the Services described for the package, including, on the DPO packages, the named DPO role, the documentation, and the breach cover, and is not metered by hours. The standard Included Hours are: Privacy Advisory, 2 hours per month; DPO Foundation, 4 hours per month; DPO Partner, 8 hours per month; DPO Complete, unlimited. Enterprise Included Hours are as set out in the Order Form. Included Hours do not accrue and do not roll over between months.
Time beyond the Included Hours is billed only with the Customer's approval in advance, at a single rate of EUR 280 per hour for the Principal and named DPO. No other hourly rate applies.
Payment Terms. Invoices are issued monthly and are due within 30 days of the invoice date. Where Fees are collected by subscription, they are collected automatically in accordance with that subscription.
Late Payment. Late payments incur interest at a rate of 2 percent per month on any amount remaining unpaid after the due date.
Annual Increase. The Fees set out in the Order Form increase by 4 percent annually, starting 1 year from the Start Date.
5. Expenses
The Customer will reimburse Engage for reasonable pre-approved expenses incurred in connection with the Services.
6. Confidentiality
Both parties agree to keep all Engage and Customer proprietary information, tools, trade secrets, and similar data confidential, and to share it only with those who have a need to know, both during and after the Term. The only exception is where information is required to be provided as part of a legal requirement, in which case the party subject to that requirement must notify the other in writing. The Customer agrees not to copy, reverse engineer, or create any works from the tools or Services originating from Engage unless prior consent is given by Engage.
7. Intellectual Property
Engage's own reusable methodologies, frameworks, templates, and materials remain the intellectual property of Engage. The Customer's right to use those underlying reusable frameworks and templates is limited to the duration of the Term.
The compliance deliverables and work product that Engage develops specifically for the Customer, including the Customer's records of processing, policies, and assessments, belong to the Customer, and the Customer may continue to use them after this Agreement ends.
The Customer may not sub-lease or transfer Engage's tools or intellectual property without the prior written approval of Engage.
8. Liability and Indemnification
Limitation of Liability. The Customer agrees that Engage (whether in contract, tort, or otherwise for services rendered under this Agreement) holds no representations, warranties, or guarantees in connection with the Services or towards compliance with data protection laws, and will not be held responsible for any direct or indirect damage as a result of the provision of these Services. Total liability, in any case, to the Customer shall not exceed the lesser of (a) up to 12 months of Fees paid, excluding Initial Fees, and (b) the amount of recoverable insurance, regardless of whether any action or claim is based upon contract, warranty, tort (including negligence) or strict liability.
Indemnification. Each party (the "Indemnifying Party") agrees to indemnify, defend, and hold harmless the other party (the "Indemnified Party"), its affiliates, officers, agents, employees, and permitted successors and assigns, from and against any and all losses, damages, liabilities, deficiencies, claims, actions, judgments, settlements, interest, awards, penalties, fines, costs, or expenses of whatever kind (including reasonable attorneys' fees) arising out of or resulting from (i) the breach of this Agreement by the Indemnifying Party; (ii) the gross negligence or wilful misconduct of the Indemnifying Party; or (iii) the Indemnifying Party's violation of any law or of the rights of a third party.
9. Dispute Resolution
Any disputes arising under this Agreement shall be resolved through mediation in accordance with the laws of the Netherlands.
10. Independent Contractor
Engage is an independent contractor and not an employee of the Customer. This Agreement does not create a partnership, joint venture, or any other fiduciary relationship.
11. Force Majeure
In the event of a force majeure (defined as unforeseeable circumstances including but not limited to acts of God, war, terrorism, civil unrest, extreme weather, or government action), either party will be excused from performing its obligations under this Agreement to the extent that performance is prevented by such events, without liability to the other party.
12. Data Protection
Where Engage processes personal data on behalf of the Customer in the course of providing the Services, Engage acts as a processor and the Customer acts as a controller. That processing is governed by the Data Processing Agreement at Annex A, which forms part of this Agreement.
Where Engage provides a named DPO, the DPO performs the tasks set out in GDPR Article 39 and is bound by secrecy and confidentiality in the performance of those tasks in accordance with GDPR Article 38(5).
Where an applicable Data Protection Law other than the GDPR imposes an equivalent data protection officer, privacy officer, or local representative requirement on the Customer, the parties will agree in writing whether the named DPO also fulfils that role. Unless agreed in writing, the named DPO fulfils the role of Data Protection Officer under the GDPR only.
13. Order of Precedence
In the event of conflict, the following order of precedence applies:
- Annex A (Data Processing Agreement), in respect of data protection matters;
- the Order Form, including any Custom Terms;
- the Service Level Agreement;
- this Services Agreement.
14. Entire Agreement
This Agreement, together with the Order Form, the Service Level Agreement, and Annex A, constitutes the entire agreement between the parties and supersedes all prior communications, agreements, and understandings, whether written or oral. Where the Customer accepts these terms electronically at online checkout, that acceptance has the same effect as signature of the Order Form.
15. Amendment
This Agreement may only be amended in writing and agreed by both parties.
16. Notices
All notices under this Agreement shall be in writing and sent digitally to the contact addresses set out in the Order Form.
17. Governing Law
This Agreement shall be governed by and construed in accordance with the laws of the Netherlands.
Annex A: Data Processing Agreement
This Data Processing Agreement (the "DPA") forms part of the Agreement between Engage Data Consulting BV ("Engage") and the Customer, and applies where Engage processes personal data on behalf of the Customer in the course of providing the Services.
1. Definitions
1.1 "Data Protection Laws" means all laws and regulations relating to the processing of personal data, privacy, and data protection that apply to the Customer or to Engage's provision of the Services, including as applicable: Regulation (EU) 2016/679 (the "GDPR"); the UK GDPR and the Data Protection Act 2018; the Swiss Federal Act on Data Protection; Directive 2002/58/EC and its national implementations; the California Consumer Privacy Act as amended by the California Privacy Rights Act, and the comprehensive consumer privacy laws of other United States jurisdictions; the Personal Information Protection and Electronic Documents Act (Canada); the Lei Geral de Protecao de Dados (Brazil); the Protection of Personal Information Act (South Africa); the Personal Data Protection Act (Singapore); the Privacy Act 1988 and the Australian Privacy Principles (Australia); the personal data protection laws of the United Arab Emirates and of the Kingdom of Saudi Arabia; the Personal Information Protection Law (People's Republic of China); the Act on the Protection of Personal Information (Japan); the Personal Information Protection Act (Republic of Korea); the Digital Personal Data Protection Act (India); and any other applicable data protection or privacy law, in each case as amended, superseded, or replaced from time to time.
1.2 The terms "controller", "processor", "personal data", "processing", "data subject", "special categories of personal data", "personal data breach", and "supervisory authority" have the meanings given to them in the GDPR. Where a Data Protection Law other than the GDPR applies to the processing, the equivalent terms and concepts under that law apply, including "business", "service provider", "consumer", "sale", and "sharing" under United States state privacy laws.
1.3 References in this DPA to Articles of the GDPR are included as the baseline standard. Where another Data Protection Law applies, the corresponding obligation under that law applies in addition, and Engage shall meet the higher standard where the two differ.
2. Roles of the Parties
2.1 The Customer is the controller and Engage is the processor in respect of the personal data described in Appendix 1.
2.2 Engage acts as an independent controller in respect of the business contact details of the Customer's personnel that Engage processes for its own account management, billing, and legal compliance purposes.
2.3 Where Engage provides a named DPO, the DPO acts in accordance with GDPR Articles 37 to 39. The DPO role is not a processing role, and nothing in this DPA limits the independence of the DPO under GDPR Article 38(3).
3. Processing Instructions
3.1 Engage shall process personal data only on the documented instructions of the Customer, including with regard to transfers of personal data to a third country, unless required to do so by Union or Member State law to which Engage is subject. In that case, Engage shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
3.2 The Agreement, the Order Form, and this DPA constitute the Customer's complete and final documented instructions to Engage. Any additional instructions must be agreed in writing.
3.3 Engage shall immediately inform the Customer if, in its opinion, an instruction infringes any applicable Data Protection Law.
4. Confidentiality of Personnel
Engage shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5. Security of Processing
Engage shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as required by GDPR Article 32 and by any equivalent security obligation under other applicable Data Protection Laws. The measures implemented by Engage as at the Start Date are set out in Appendix 2.
6. Sub-processors
6.1 The Customer gives Engage general written authorisation to engage sub-processors. The sub-processors engaged as at the Start Date are listed in Appendix 3. The current list of sub-processors is published and maintained by Engage at https://www.engagecompliance.co/privacy.
6.2 Engage publishes and maintains the current list of sub-processors at https://www.engagecompliance.co/privacy, where the Customer may subscribe to receive notification of changes. Publication of an intended addition or replacement at that address constitutes notice to the Customer, and Engage will publish such changes at least 30 days in advance, giving the Customer the opportunity to object on reasonable data protection grounds. It is the Customer's responsibility to subscribe to notifications at that address if it wishes to be notified directly. If the Customer objects and the parties cannot agree a resolution, the Customer may terminate the Agreement on written notice in respect of the affected Services, without penalty.
6.3 Engage shall impose on each sub-processor data protection obligations no less protective than those set out in this DPA, and remains fully liable to the Customer for the performance of each sub-processor's obligations.
7. Data Subject Rights
Taking into account the nature of the processing, Engage shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in the fulfilment of the Customer's obligation to respond to requests from individuals exercising their rights under Chapter III of the GDPR and any equivalent individual rights under other applicable Data Protection Laws, including rights of access, correction, deletion, portability, objection, opt-out of sale or sharing, and limitation of the use of sensitive personal information. Fulfilment of individual rights requests remains the responsibility of the Customer.
8. Assistance to the Customer
Engage shall assist the Customer in ensuring compliance with the obligations set out in GDPR Articles 32 to 36, and with equivalent obligations under other applicable Data Protection Laws, taking into account the nature of the processing and the information available to Engage. This includes assistance in relation to security of processing, personal data breach notification, data protection impact assessments or equivalent risk assessments, and prior consultation with a supervisory authority.
9. Personal Data Breach
Engage shall notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Customer's personal data, and shall provide the information reasonably available to it in order to enable the Customer to meet its obligations under GDPR Articles 33 and 34 and any equivalent breach notification obligations under other applicable Data Protection Laws. Breach forensics, and breach notification to supervisory authorities or to individuals, are excluded from the Services unless otherwise agreed in writing.
10. Deletion or Return of Personal Data
Upon termination of the Agreement, or at the Customer's written request, Engage shall, at the Customer's choice, delete or return all personal data processed on behalf of the Customer and delete existing copies, unless applicable law requires storage of the personal data. Engage shall provide written confirmation of deletion or return upon request.
11. Audits and Information
Engage shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in GDPR Article 28, and with equivalent processor obligations under other applicable Data Protection Laws, and shall allow for and contribute to audits, including inspections, conducted by the Customer or by another auditor mandated by the Customer. Audits shall take place on reasonable written notice, no more than once in any 12 month period unless required by a supervisory authority or following a personal data breach, during working hours, and subject to confidentiality obligations.
12. International Transfers
12.1 Where personal data is transferred outside the jurisdiction in which it was collected, and that transfer is restricted by applicable Data Protection Laws, Engage shall ensure that the transfer is made under an appropriate and lawful transfer mechanism.
12.2 For transfers from the European Economic Area, this includes the European Commission's Standard Contractual Clauses, an adequacy decision, or certification under the EU-US Data Privacy Framework. For transfers from the United Kingdom, this includes the International Data Transfer Agreement or the UK Addendum to the Standard Contractual Clauses. For transfers from Switzerland, this includes the Swiss Addendum to the Standard Contractual Clauses. For transfers from any other jurisdiction, Engage shall use a transfer mechanism recognised as lawful under the applicable Data Protection Law.
12.3 Engage shall implement supplementary measures where these are required to ensure an adequate level of protection.
12.4 The countries in which sub-processors process personal data are identified in Appendix 3.
13. Jurisdiction-Specific Terms
13.1 United States state privacy laws. Where the Customer is subject to the California Consumer Privacy Act as amended, or to any other comprehensive United States state privacy law, and Engage processes personal information on the Customer's behalf, Engage acts as a service provider or processor as defined under that law. Engage shall not: (a) sell or share the personal information; (b) retain, use, or disclose the personal information for any purpose other than performing the Services specified in the Agreement, or as otherwise permitted by that law; (c) retain, use, or disclose the personal information outside the direct business relationship between Engage and the Customer; or (d) combine the personal information with personal information received from or on behalf of any other person, except as permitted by that law. Engage certifies that it understands and will comply with these restrictions. The Customer may take reasonable and appropriate steps to ensure that Engage's use of the personal information is consistent with the Customer's obligations under that law, and to stop and remediate any unauthorised use.
13.2 United Kingdom. Where the UK GDPR applies, references in this DPA to the GDPR are read as references to the UK GDPR, and references to a supervisory authority are read as references to the Information Commissioner's Office.
13.3 Switzerland. Where the Swiss Federal Act on Data Protection applies, references to a supervisory authority are read as references to the Federal Data Protection and Information Commissioner.
13.4 Other jurisdictions. Where any other Data Protection Law requires specific contractual terms between a controller and a processor, or their equivalents, the parties shall enter into those terms in writing. Until they do so, Engage shall process the personal data in a manner consistent with the obligations set out in this DPA and with the requirements of that law, to the extent that Engage has been informed of those requirements by the Customer.
14. Special Categories of Personal Data
The Customer shall not provide, and shall take reasonable steps not to make available to Engage, special categories of personal data, sensitive personal information, criminal offence data, or personal data relating to the Customer's own customers or end users, except where strictly necessary for the Services and agreed in writing in advance.
15. Liability
The limitations of liability set out in the Services Agreement apply to this DPA.
Appendix 1: Details of the Processing
Appendix 2: Technical and Organisational Measures
Engage maintains the following technical and organisational measures:
Appendix 3: Sub-processors
The following sub-processors are engaged by Engage as at the Start Date. The current list of sub-processors is published and maintained by Engage at https://www.engagecompliance.co/privacy, and that published list prevails over the table below where the two differ.
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Google Ireland Limited and Google LLC | Productivity, communication and document storage services | European Union and United States |
| Anthropic PBC | Artificial intelligence services, on a no-training basis | United States |
| Voyage AI | Artificial intelligence services | United States |
| Neon Inc | Database hosting | European Union (Frankfurt) |
| Vercel Inc | Application hosting | European Union (Frankfurt region) |
| Resend | Transactional email delivery | European Union and United States |
| Stripe Payments Europe Limited | Payment processing (billing data only) | European Union |
| HubSpot Inc | Customer relationship management (business contact details only) | United States |
Changes to this list are published at https://www.engagecompliance.co/privacy in accordance with clause 6.2 of this DPA.