This translation is provided for information only. In case of any discrepancy, the Dutch version prevails. Read the Dutch version

Legal

Data processing agreement

Last updated: 8 September 2026

This data processing agreement forms an integral part of every assignment in which Colddrop processes personal data on behalf of the client. The client acts as controller, Contento GCV acts as processor.

1. Subject matter and duration

The processor processes personal data solely in order to carry out the controller’s assignment: creating, delivering and measuring drops. This agreement applies for as long as the processor processes data on behalf of the controller.

2. Nature and purpose of the processing

Collection, organisation, storage, use for personalisation, printing or baking, delivery, and recording of scans and interactions on the personal landing page. Solely for the campaign concerned, never for the processor’s own purposes.

3. Categories of data subjects and data

Data subjects: the recipients of a drop designated by the controller. Data: first name and surname, company, job title, delivery address, and scan and interaction data from the landing page.

4. Instructions

The processor acts solely on documented instructions from the controller. If the processor considers that an instruction infringes the applicable legislation, it shall report this.

5. Confidentiality

The processor undertakes to maintain confidentiality and ensures that anyone with access to the data is bound by the same duty of confidentiality.

6. Security measures

The processor takes appropriate technical and organisational measures: access on a need-to-know basis, encryption where appropriate, storage within the EEA as a rule, and limitation of the retention period for address data to thirty days after delivery.

7. Sub-processors

The processor may engage sub-processors: hosting provider, printer and bakery, courier service, email platform, payment provider and analytics tools. Each sub-processor is bound by the same obligations. In the event of a change of sub-processor, the processor informs the controller in advance, so that the controller can object.

8. Assistance with data subjects’ rights

The processor assists the controller in responding in a timely manner to requests from data subjects (access, rectification, erasure and the other rights).

9. Personal data breach notification

The processor notifies the controller of a personal data breach without undue delay and at the latest within forty-eight hours of becoming aware of it, providing all the information the controller needs to comply with its own notification obligation.

10. Deletion at the end of the assignment

After the end of the assignment, the processor deletes the personal data or returns it, at the controller’s choice, except for what must be retained by law or is needed for the suppression list.

11. Right to audit

The controller may, subject to reasonable notice and without unnecessarily disrupting business operations, audit or have audited compliance with this agreement.

Start with your account list.

We find the trigger, you have the conversations.

Cold call.Cold mail.Colddrop.Cold call.Cold mail.Colddrop.