Data processing agreement

Last updated: 4 October 2026

This data processing agreement ("DPA") is part of our terms of service. It applies automatically to every organisation that uses High Fives, so there is nothing to sign. Need a signed copy for your records? Email info@highfives.team and we'll send one.

1. Parties and roles

This DPA covers the personal data of the participants on your board. Data about your organisation as our customer (your order, invoices and contact details) is described in our privacy policy; for that data we are the controller ourselves.

2. What we process, and why

3. Your instructions

We process the personal data only on your documented instructions. These terms, this DPA and the settings you choose on your board are those instructions. If we are ever legally required to process data in another way, we tell you first, unless the law forbids that. If we think an instruction breaks data protection law, we tell you.

4. Confidentiality

Everyone who works on High Fives for us and can access personal data is bound to confidentiality.

5. Security

We take appropriate technical and organisational measures to protect the personal data. They are described in Annex 1 and we keep them up to date.

6. Sub-processors

You give us general permission to use sub-processors. The current ones are listed in Annex 2. Each one is bound by a written agreement with data protection obligations at least as strict as this DPA. We announce a new or replacing sub-processor at least 30 days in advance by email to the address used for your order. If you have a reasonable objection, tell us within that period; if we can't solve it together, you can end your plan and we refund the unused part of a prepaid period.

7. Helping you

8. When your plan ends

When your plan ends, the board stays readable for 30 days, so you can see the final standings or renew. After that we delete the board and all personal data on it. Copies in our backups are deleted within a further 30 days at most. If you want your board deleted sooner, email us.

9. Data breaches

If we discover a personal data breach that affects your board, we inform you without undue delay, and in any case within 48 hours of discovering it. We tell you what happened, what data is involved, what we are doing about it and who you can contact, so you can meet your own obligations, such as notifying the supervisory authority within 72 hours.

10. Information and audits

On request, we give you the information you need to check that we keep to this DPA. If that isn't enough, you can have an audit done by an independent auditor bound to confidentiality, at your own cost, with at least 30 days' notice and at most once a year, unless a breach or a supervisory authority gives reason for more.

11. Transfers outside the EU

Your board's data is stored in the EU. Some sub-processors are companies based in the United States; where their service could involve a transfer outside the EU, it is covered by the EU-US Data Privacy Framework or the European Commission's standard contractual clauses.

12. Liability, duration and law

The liability rules in our terms of service also apply to this DPA, as far as the law allows. This DPA lasts as long as we process personal data for you. Dutch law applies, and disputes go to the competent court in the district of Oost-Brabant. If this DPA and the terms of service conflict on data protection, this DPA prevails.

Annex 1: Security measures

Annex 2: Sub-processors