FAQ Plus

Data processing agreement

Effective 1 September 2026, version 1. This agreement is part of the FAQ Plus terms of service and applies to every customer. FAQ Plus is operated by Solid Software B.V., Rümkelaan 32, Utrecht, Netherlands, KvK 94194432 ("we", the processor). The customer is the business holding the FAQ Plus account ("you", the controller).

1. Roles and scope

2. Instructions

3. Confidentiality

Persons authorised by us to process the data are bound by confidentiality. We do not sell the data and do not use it to train AI models.

4. Security

We implement and maintain the technical and organisational measures in Annex 2, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, so that they provide a level of security appropriate to the risk (art. 32 GDPR). We may update Annex 2, but not in a way that lowers the level of protection.

5. Sub-processors

6. Assistance

7. Personal data breach

We notify you without undue delay after becoming aware of a personal data breach affecting the data in Annex 1, at your account email address. The notification describes, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We document breaches and keep you informed as the investigation develops.

8. Deletion and return

9. Audits

We make available to you the information necessary to demonstrate compliance with art. 28 GDPR, in the first place through this agreement, the privacy statement and Annex 2. Where the GDPR gives you an audit right that this information does not satisfy, we allow an audit by you or an auditor mandated by you, at most once per twelve months, on 30 days written notice, during business hours, without access to other customers' data, at your cost.

10. International transfers

We process and store the data in Annex 1 in the European Union. Where a sub-processor processes data outside the EU or EEA, the transfer is covered by the mechanism named in Annex 3 (an adequacy decision, the EU-US Data Privacy Framework, or the European Commission's Standard Contractual Clauses).

11. Final provisions

Annex 1: processing details

Annex 2: technical and organisational measures

Annex 3: sub-processors

Stripe processes billing data as an independent controller and is therefore not a sub-processor under this agreement.