Data processing agreement
Last updated: 4 October 2026
This data processing agreement ("DPA") is part of our terms of service. It applies automatically to every organisation that uses High Fives, so there is nothing to sign. Need a signed copy for your records? Email info@highfives.team and we'll send one.
1. Parties and roles
- The controller is the organisation that orders and runs a High Fives board ("you"). You decide what the challenge is and who takes part.
- The processor is e-campaigne.me, Van Everdingenstraat 22, 5643 VB Eindhoven, the Netherlands, KvK 99381435, which provides High Fives ("we").
This DPA covers the personal data of the participants on your board. Data about your organisation as our customer (your order, invoices and contact details) is described in our privacy policy; for that data we are the controller ourselves.
2. What we process, and why
- Purpose: only to provide your challenge board: showing it, letting participants join and log their contributions, and keeping it safe and backed up.
- Data subjects: your participants (usually your employees or members) and the people who manage the board for you.
- Personal data: the display name each participant chooses, their team, what they log (for example steps, active minutes, pages read, bingo squares or products sold) with the time of their latest entry, the high fives they send and receive on a High Five wall (with the short message and the time), and the content your administrators add to the board (team names, the reward text, the link to your logo).
- No sensitive data: the service is not meant for special categories of personal data, such as medical information. Please don't ask participants to enter it.
- Duration: for as long as your plan runs, plus the 30-day read-only period after it ends. Then the board is deleted (see section 8).
3. Your instructions
We process the personal data only on your documented instructions. These terms, this DPA and the settings you choose on your board are those instructions. If we are ever legally required to process data in another way, we tell you first, unless the law forbids that. If we think an instruction breaks data protection law, we tell you.
4. Confidentiality
Everyone who works on High Fives for us and can access personal data is bound to confidentiality.
5. Security
We take appropriate technical and organisational measures to protect the personal data. They are described in Annex 1 and we keep them up to date.
6. Sub-processors
You give us general permission to use sub-processors. The current ones are listed in Annex 2. Each one is bound by a written agreement with data protection obligations at least as strict as this DPA. We announce a new or replacing sub-processor at least 30 days in advance by email to the address used for your order. If you have a reasonable objection, tell us within that period; if we can't solve it together, you can end your plan and we refund the unused part of a prepaid period.
7. Helping you
- Requests from participants: if a participant asks to see, correct or delete their data, we help you respond. You can reset a board yourself at any time; to remove a single participant, email us and we do it for you. If a participant contacts us directly, we pass the request on to you.
- Other obligations: where needed, we help you with a data protection impact assessment and with questions from a supervisory authority, as far as these concern our service.
8. When your plan ends
When your plan ends, the board stays readable for 30 days, so you can see the final standings or renew. After that we delete the board and all personal data on it. Copies in our backups are deleted within a further 30 days at most. If you want your board deleted sooner, email us.
9. Data breaches
If we discover a personal data breach that affects your board, we inform you without undue delay, and in any case within 48 hours of discovering it. We tell you what happened, what data is involved, what we are doing about it and who you can contact, so you can meet your own obligations, such as notifying the supervisory authority within 72 hours.
10. Information and audits
On request, we give you the information you need to check that we keep to this DPA. If that isn't enough, you can have an audit done by an independent auditor bound to confidentiality, at your own cost, with at least 30 days' notice and at most once a year, unless a breach or a supervisory authority gives reason for more.
11. Transfers outside the EU
Your board's data is stored in the EU. Some sub-processors are companies based in the United States; where their service could involve a transfer outside the EU, it is covered by the EU-US Data Privacy Framework or the European Commission's standard contractual clauses.
12. Liability, duration and law
The liability rules in our terms of service also apply to this DPA, as far as the law allows. This DPA lasts as long as we process personal data for you. Dutch law applies, and disputes go to the competent court in the district of Oost-Brabant. If this DPA and the terms of service conflict on data protection, this DPA prevails.
Annex 1: Security measures
- Location: boards and their database are hosted in the EU (Frankfurt, Germany).
- Encryption in transit: every connection uses HTTPS, and browsers are told to always use it (HSTS).
- Access to a board: a board can only be opened with its access code; its settings need the admin PIN. Admin PINs are stored only in hashed form. Repeated wrong codes or PINs are blocked for a while.
- Data minimisation: participants need no account, email address or password; a display name is enough.
- Protection of the web pages: strict security headers (such as a content security policy) and no third-party tracking or advertising scripts on the boards.
- Backups: encrypted before they leave the server, stored in the EU, kept for at most 30 days. Restoring from backup has been tested.
- Access to systems: only we have access to the hosting and storage accounts, protected with strong, unique passwords and two-factor authentication.
- Deletion: boards are deleted automatically 30 days after their plan ends.
Annex 2: Sub-processors
- Render Services, Inc. — hosting of the boards and their database, in Frankfurt, Germany.
- Cloudflare, Inc. — network and domain names for the board addresses, and storage of the encrypted backups in its EU jurisdiction.