Cutready

Data processing agreement

Version 1 · in force from 28 September 2026 · Nederlands

A translation. The Dutch text (Verwerkersovereenkomst) is the one that applies; where the two differ, the Dutch text prevails.

This data processing agreement belongs to Cutready's terms and conditions and forms part of them. It applies between the customer who uses Cutready ("controller", "the customer") and Maakfabriek de Laat BV, Broekkant 41, 6021 CS Budel, the Netherlands, Chamber of Commerce (KVK) 99065363, trading as Cutready ("processor", "we"). By using Cutready, the customer accepts this agreement.

1. Subject

  1. The customer puts personal data into Cutready - mainly data about their own customers in projects and quotes. For that data the customer is the controller and we are the processor within the meaning of Article 28 of the GDPR.
  2. We process that data only to provide the service as described in the terms and conditions, and only on the customer's written instructions. The customer's use of the service counts as those instructions. If we believe an instruction breaks the law, we say so straight away.

2. Which data, about whom

Data subjectsDataPurpose
The customer's customers (end customers)Name, address, reference, order number; what a design, project or quote says about themDesigns, projects, quotes and production
The customer's employeesName, e-mail address, role, what they do in the service Use of the service

Special categories of personal data (such as health) do not belong in Cutready; the customer does not put them in.

3. Duration

  1. This agreement runs as long as we process personal data for the customer.
  2. After it ends, the customer can export their data for another 30 days. After that we delete it, unless the law requires us to keep it longer. Backups expire by themselves within 14 days after that.

4. Confidentiality and staff

  1. Everyone at our end with access to the data is bound to confidentiality.
  2. Our staff open the customer's data only when needed: for a support question from the customer, or to fix a fault. Opening a design with a support question is logged.

5. Security

We take appropriate technical and organisational measures (Article 32 GDPR), at least:

6. Sub-processors

  1. The customer consents to the sub-processors below. With each we have arrangements at least as protective as this agreement.
  2. We announce a new or different sub-processor at least 30 days in advance. The customer can object; if we cannot resolve it, they can terminate the agreement.
Sub-processorWhat forWhere
HostingerServer, database, backupsEuropean Union
AnthropicThe AI assistant, with the customer's API key - or, for a demo on a free voucher, with oursUnited States
RunPodRenders of a design, without the names of customers or order numbers Data centres in the European Union
BrevoE-mailFrance (EU)

Only Anthropic processes data outside the EU (United States). That transfer is based on the European Commission's standard contractual clauses, as included in Anthropic's data processing agreement. Where the customer uses their own key, they also enter into their own agreement with Anthropic for the AI assistant.

7. Data breaches

  1. If we discover a security breach affecting the customer's data, we report it to the customer without undue delay and at the latest within 48 hours of discovering it, with what we know at that moment: what happened, which data and data subjects it affects, the consequences and what we are doing.
  2. The customer decides whether to report the breach to the Dutch Data Protection Authority and to data subjects; we help with that.

8. Assistance to the customer

  1. As far as is reasonable, we help the customer with requests from data subjects (access, correction, deletion) and with a data protection impact assessment. A request that reaches us, we pass on to the customer.
  2. The customer can view, change, export and delete most data themselves in the service.

9. Audit

  1. On request we give the customer the information needed to show that we comply with this agreement. An audit by an independent expert is possible after consultation, at the customer's expense, and at most once a year, unless there is a specific reason.

10. Liability and final provisions

  1. For liability, the provisions of the terms and conditions apply, as far as the GDPR allows.
  2. Where they conflict, this agreement prevails over the terms and conditions as regards the processing of personal data.
  3. Dutch law applies; disputes go to the District Court of Oost-Brabant.