Data Processing Agreement
This Data Processing Agreement sets out the arrangements between an organisation that uses MilMap and thereby acts as controller, and Onavan B.V. (trading under the name "MilMap"), which processes personal data as processor in that context. This agreement complies with Article 28 GDPR and forms an integral part of the Terms of Service. Where this agreement refers to the Privacy Policy, the Terms of Service or the Data & Security document, those documents apply as a supplement hereto.
Contents
- 1. Parties and definitions
- 2. Subject matter, nature and duration of the agreement
- 3. Subject matter of the processing: nature, purpose, types of personal data and categories of data subjects
- 4. Instructions of the controller
- 5. Confidentiality
- 6. Security of processing
- 7. Engagement of sub-processors
- 8. Assistance to the controller
- 9. Personal data breaches and notifications
- 10. Return and deletion of data upon termination
- 11. Audits, monitoring and accountability
- 12. Transfers of personal data outside the EEA
- 13. Liability and indemnification
- 14. Final provisions and governing law
1. Parties and definitions
This Data Processing Agreement (hereinafter: the "Data Processing Agreement") is entered into between:
- the organisation (for example a unit, team, service or company) that uses MilMap and that determines the purposes and means of the processing of personal data within its own environment, hereinafter: the "Controller"; and
- Onavan B.V., established in the Netherlands, trading under the name "MilMap" (hereinafter: "MilMap", "Processor" or "we"), which, in the context of the Controller's use, processes personal data on the instructions of and on behalf of the Controller.
In this Data Processing Agreement, the following terms have the meanings assigned to them below; terms that are not defined have the meaning given to them by the General Data Protection Regulation (GDPR).
- GDPR: Regulation (EU) 2016/679 (General Data Protection Regulation), and the Dutch implementing legislation based thereon.
- Personal data: any information relating to an identified or identifiable natural person that MilMap processes on behalf of the Controller under this Data Processing Agreement.
- Processing: any operation performed on personal data, such as collection, recording, storage, consultation, transmission, encryption, erasure and destruction.
- Data subject: the natural person to whom the personal data relate.
- Sub-processor: a third party engaged by MilMap that processes personal data on MilMap's instructions.
- Personal data breach: a breach of security leading, accidentally or unlawfully, to the destruction, loss, alteration, or unauthorised disclosure of, or access to, personal data processed.
- Underlying Agreement: the Terms of Service and/or the subscription under which the Controller uses MilMap.
For general enquiries, MilMap can be reached at support@milmap.nl. For privacy and GDPR matters, including notifications under this Data Processing Agreement, MilMap can be reached at privacy@milmap.nl.
This Data Processing Agreement covers only those processing operations in which MilMap acts as processor. For the personal data that MilMap processes for its own purposes — such as account management, invoicing via Stripe, security, and the operation and improvement of the platform — MilMap itself acts as controller; those processing operations are described in the Privacy Policy and fall outside the scope of this Data Processing Agreement.
2. Subject matter, nature and duration of the agreement
Subject matter. MilMap is an online mapping, navigation and location platform (web/PWA and app) for, among others, military personnel, SAR and emergency services, and outdoor and expedition users. When an organisation uses MilMap to collaborate — for example through missions, teams, shared maps, marked locations, live location sharing and the end-to-end encrypted chat — MilMap thereby processes personal data of that organisation's members and invitees. For those processing operations, this Data Processing Agreement sets out the mutual rights and obligations in accordance with Article 28 GDPR.
Nature of the agreement. This Data Processing Agreement forms an integral part of the Underlying Agreement (the Terms of Service and the chosen subscription) and is concluded at the moment the Controller starts using MilMap in a context in which it acts as controller. This Data Processing Agreement does not require separate signature in order to take effect.
Duration. This Data Processing Agreement applies for the duration of the Underlying Agreement and terminates by operation of law as soon as the latter ends. Obligations that by their nature are intended to survive termination — including confidentiality, the return and deletion of data (Section 10) and liability (Section 13) — shall remain in force after termination.
Allocation of roles. The Controller determines the purposes and means of the processing and is responsible for its lawfulness, including a valid legal basis for processing and the provision of information to data subjects. MilMap processes the personal data solely on the instructions of and in accordance with the directions of the Controller, as further set out in Section 4.
3. Subject matter of the processing: nature, purpose, types of personal data and categories of data subjects
This section describes, by way of annex to this Data Processing Agreement, the subject matter of the processing. Through its actual use of MilMap, the Controller further specifies this description and warrants that it is accurate and complete.
Nature of the processing. MilMap performs, among others, the following operations on behalf of the Controller:
- storing and hosting account data, maps, routes, marked locations, mission and team data;
- processing and displaying (live) location data and sharing it within a team or mission;
- transmitting and storing chat messages in end-to-end encrypted form (exclusively as unreadable ciphertext, see Section 6);
- performing map, geocoding, weather and elevation queries in support of the functionality;
- creating backups and securing, maintaining and keeping the platform available.
Purpose of the processing. The processing serves solely to deliver the MilMap functionality selected by the Controller: searching for locations, planning routes, navigating, sharing and managing maps, marking locations, MGRS grid coordinates, bearing calculation, live location sharing, weather and elevation information, missions and teams, and the encrypted chat. Location data is not sold and is not used for advertising purposes.
Types of personal data. Depending on the functionality used, the processing may concern:
- account data (such as name, username and email address);
- location data, including (live) position, routes, marked points and coordinates;
- collaboration data within missions and teams (such as roles, membership and shared content);
- chat content, which is stored by MilMap exclusively as end-to-end encrypted ciphertext;
- technical and usage data necessary for operation and security.
Categories of data subjects. The processing concerns the natural persons whose data the Controller processes within MilMap, including:
- members of the organisation, unit or team;
- users invited or added by the Controller;
- other persons whose personal data the Controller enters into or shares via the platform.
4. Instructions of the controller
MilMap processes the personal data solely on the basis of written, documented instructions from the Controller, unless MilMap is required to process by a legal obligation; in the latter case, MilMap shall inform the Controller of that legal requirement before processing, unless that law prohibits such notification on important grounds of public interest.
This Data Processing Agreement, the Underlying Agreement and the configuration and usage options the Controller selects within MilMap jointly constitute the documented instructions. Additional or deviating instructions shall be agreed in writing (including by email to privacy@milmap.nl). MilMap may charge a reasonable fee for carrying out instructions that go beyond the standard functionality.
MilMap does not process the personal data for its own purposes, nor for any purposes other than those instructed by the Controller. In particular, location data is not sold and is not used for advertising.
If MilMap is of the opinion that an instruction infringes the GDPR or other data protection provisions, MilMap shall inform the Controller thereof without delay. MilMap is not obliged to carry out an instruction that it reasonably believes to be unlawful.
5. Confidentiality
MilMap shall keep confidential the personal data it processes on behalf of the Controller and shall not disclose it to third parties, except to the extent necessary for the performance of this Data Processing Agreement, through the engagement of sub-processors in accordance with Section 7, or pursuant to a legal obligation.
MilMap ensures that the persons authorised to access the personal data under its authority:
- have committed themselves to confidentiality, either under a statutory obligation of confidentiality or under a contractual confidentiality obligation;
- are granted access to the personal data only to the extent necessary for their duties (need-to-know);
- have been instructed and, where appropriate, trained to handle personal data with due care and in accordance with this Data Processing Agreement.
This confidentiality obligation shall remain in force after the termination of this Data Processing Agreement and after the end of the involvement of the persons concerned. In addition, a technical safeguard applies to the content of the chat: due to the end-to-end encryption, MilMap has no access to the readable message content (see Section 6).
6. Security of processing
MilMap implements appropriate technical and organisational measures to protect the personal data against loss or against any form of unlawful processing, in accordance with Article 32 GDPR and in line with the principles of privacy by design, privacy by default and data minimisation. The current measures are described in more detail in the Data & Security document, which applies as a supplement to this Data Processing Agreement.
These measures include in any event:
- encryption of data in transit and, where appropriate, at rest;
- access management on a need-to-know basis, with authentication and access logging;
- server hosting with a hosting partner within the EU;
- measures aimed at the confidentiality, integrity, availability and resilience of the systems, including backups and recovery procedures;
- periodic evaluation and, where necessary, updating of the security measures.
End-to-end encrypted chat. The chat feature is end-to-end encrypted by default using sealed-box encryption based on modern open cryptography (NaCl/libsodium). Messages are encrypted on the sender's device and only decrypted on the recipient's device; MilMap stores nothing but unreadable ciphertext and has no access to the content. Every user has a key pair; by default, the private key remains on the device. Group messages are sealed separately for each recipient. Optional synchronisation between devices takes place via a personal PIN code: the private key is encrypted locally with a key derived from that PIN (Argon2id) and is stored on the server only as ciphertext — MilMap does not know the PIN.
In determining the appropriate level of security, MilMap takes into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of data subjects.
7. Engagement of sub-processors
The Controller hereby grants MilMap general authorisation to engage sub-processors for the performance of the processing. At the time of this Data Processing Agreement, MilMap uses the following categories of sub-processors:
- Mapbox — map tiles and geocoding;
- a weather service API — weather information;
- an elevation API — elevation information;
- an EU hosting partner — server hosting within the EU;
- Stripe — payments and subscriptions;
- an email/SMTP service — transactional email.
MilMap imposes on each sub-processor, by contract, data protection obligations equivalent to the obligations set out in this Data Processing Agreement, in particular the obligation to implement appropriate technical and organisational security measures. MilMap remains fully liable to the Controller for the performance of the obligations by the sub-processors it engages.
Intended changes. MilMap shall inform the Controller in due time of any intended changes concerning the addition or replacement of sub-processors, thereby giving the Controller the opportunity to object to such changes. The Controller may object in writing via privacy@milmap.nl within a reasonable period (in principle 30 days) after notification, on reasonable grounds relating to data protection. If the parties are unable to reach agreement in that case, the Controller has the right to terminate the affected service or the Underlying Agreement insofar as it is affected by the sub-processor concerned.
Location data is not provided to sub-processors to be sold or to be used for advertising purposes.
8. Assistance to the controller
Taking into account the nature of the processing, MilMap shall provide the Controller with reasonable assistance in fulfilling its obligations under the GDPR.
Rights of data subjects. MilMap assists the Controller, by means of appropriate technical and organisational measures, in responding to requests from data subjects exercising their rights, including the rights of access, rectification, erasure, restriction, objection and data portability. If MilMap receives such a request directly from a data subject concerning data provided by the Controller, MilMap shall in principle not respond substantively on its own initiative, but shall refer the data subject to the Controller and inform the Controller without undue delay.
Data protection impact assessment (DPIA) and prior consultation. MilMap shall provide the Controller with reasonable assistance in carrying out a data protection impact assessment and, where applicable, in a prior consultation of the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), by providing, upon request, the information available to MilMap regarding the nature and security of the processing.
Security and notifications. MilMap shall further provide assistance in ensuring compliance with the obligations regarding the security of processing (Section 6) and the notification of personal data breaches (Section 9).
For assistance that goes beyond the standard functionality of the platform, MilMap may charge a reasonable fee; MilMap shall make this known in advance.
9. Personal data breaches and notifications
MilMap shall notify the Controller without undue delay after becoming aware of a personal data breach concerning the personal data processed on behalf of the Controller. The notification enables the Controller, where required, to comply in a timely manner — that is, where possible within 72 hours after the Controller first becomes aware of the breach — with its own notification obligation towards the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and, where applicable, towards the data subjects.
MilMap's notification shall at least contain, to the extent known at that time:
- the nature of the personal data breach, including where possible the categories and approximate number of data subjects and the categories and approximate volume of personal data concerned;
- the likely consequences of the personal data breach;
- the measures taken and proposed to address the personal data breach and to mitigate its possible adverse effects;
- the contact details for further information.
Where it is not possible to provide all information at the same time, MilMap shall provide it in phases without further undue delay. MilMap documents personal data breaches and the measures taken, and shall reasonably cooperate in investigation and remediation.
The assessment of whether a personal data breach must be notified to the Dutch Data Protection Authority and/or to data subjects, and the making of such notifications, remain the responsibility of the Controller. MilMap shall not itself notify the supervisory authority or data subjects on behalf of the Controller, unless instructed to do so in writing or where MilMap is legally required to do so. Notifications under this section are made via privacy@milmap.nl.
10. Return and deletion of data upon termination
Upon termination of this Data Processing Agreement, or earlier upon the Controller's first request, MilMap shall — at the choice of the Controller — delete or return all personal data processed on behalf of the Controller, and MilMap shall delete existing copies, unless Union or Dutch law requires MilMap to store the data for a longer period.
The deletion or return shall take place within a reasonable period after the end of the Underlying Agreement. During that period, MilMap shall limit the processing to what is necessary for the return or deletion and for the security of the data. Where return has been requested, MilMap shall provide the data in a common, structured format.
The deletion also includes the end-to-end encrypted chat ciphertext stored by MilMap. With respect to data that MilMap is required to retain under a legal obligation, the obligations under this Data Processing Agreement shall continue to apply until that data has also been deleted.
Upon request, MilMap shall provide the Controller with written confirmation that the obligations under this section have been fulfilled. These provisions are without prejudice to MilMap's own retention periods for data for which it acts as controller itself, as described in the Privacy Policy.
11. Audits, monitoring and accountability
MilMap shall make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations under Article 28 GDPR and this Data Processing Agreement.
MilMap shall allow for and contribute to audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller, subject to the following conditions:
- audits take place following prior written notice with a reasonable notice period (in principle at least 14 days), during normal business hours and in a manner that does not unnecessarily disrupt business operations or the security of other customers;
- audits take place in principle no more than once per calendar year, except in the event of a substantiated suspicion of non-compliance or a personal data breach, or at the request of a supervisory authority;
- the auditor and the Controller shall observe appropriate confidentiality and respect the confidentiality and security of the systems and of third-party data;
- MilMap may, by way of substantiation, refer to current audit reports, certifications or attestations from independent third parties, insofar as these adequately demonstrate compliance with the relevant obligations.
The costs of an audit initiated by the Controller shall be borne by the Controller; the reasonable costs incurred by MilMap for its cooperation may be charged, except where the audit reveals a failure attributable to MilMap. MilMap shall immediately inform the Controller if, in its opinion, an instruction or audit request infringes the GDPR or other data protection provisions.
12. Transfers of personal data outside the EEA
MilMap processes and hosts the personal data in principle within the European Economic Area (EEA), with a hosting partner within the EU.
To the extent that the performance of the service entails that personal data is transferred to, or accessible from, a country outside the EEA — for example because a sub-processor (such as Mapbox or Stripe) is established outside the EEA or processes data outside the EEA — such transfer shall take place only if the conditions of Chapter V GDPR are met. This means that the transfer takes place on the basis of:
- an adequacy decision of the European Commission for the country concerned; or
- appropriate safeguards, such as the Standard Contractual Clauses adopted by the European Commission, supplemented where necessary with technical and organisational measures; or
- another legal basis provided for in the GDPR.
MilMap shall not transfer personal data outside the EEA without a valid legal basis and appropriate safeguards, and shall not process personal data outside the EEA other than in accordance with the instructions of the Controller or a legal obligation. Upon request, MilMap shall provide the Controller with reasonable information about the applicable transfer mechanisms.
13. Liability and indemnification
Each party is liable for the performance of its own obligations under this Data Processing Agreement and the GDPR. MilMap's liability under this Data Processing Agreement is governed by and subject to the liability regime and the limitations and exclusions contained in the Terms of Service, to the extent permitted by mandatory law. These limitations do not apply to the extent prohibited by law, including with respect to liability towards data subjects under Article 82 GDPR.
The Controller warrants that its processing and its instructions are lawful, that a valid legal basis for processing exists and that data subjects have been duly informed. The Controller indemnifies MilMap against third-party claims, including claims by data subjects and supervisory authorities, arising from any act or omission of the Controller in breach of this Data Processing Agreement or the GDPR, including unlawful instructions and the entry of data without a valid legal basis.
MilMap indemnifies the Controller against third-party claims to the extent that they result from a failure attributable to MilMap in the performance of its obligations as processor under this Data Processing Agreement.
Where a party has paid full compensation or an administrative fine while both parties are liable, it may claim back from the other party that part of the compensation corresponding to the other party's share of responsibility for the damage, in accordance with Article 82(5) GDPR.
14. Final provisions and governing law
Order of precedence. This Data Processing Agreement forms part of the Underlying Agreement. In the event of any conflict between this Data Processing Agreement and the Terms of Service, this Data Processing Agreement shall prevail, but only with respect to matters concerning the processing and protection of personal data. In all other respects, the Terms of Service shall continue to apply in full. The Privacy Policy and the Data & Security document apply as a supplement.
Amendments. MilMap may amend this Data Processing Agreement where necessary to remain compliant with laws and regulations or to reflect changes in the services. Material amendments shall be communicated to the Controller in advance and in an appropriate manner. Other arrangements shall be amended in writing (including by email).
Severability. If any provision of this Data Processing Agreement is void or voidable, the remaining provisions shall remain in full force and effect; in that case, the parties shall consult with each other in order to replace the provision concerned with a valid provision that approximates its purport as closely as possible.
Governing law and disputes. This Data Processing Agreement is governed exclusively by Dutch law. Disputes arising from or in connection with this Data Processing Agreement shall be submitted to the competent Dutch court, without prejudice to the rights of data subjects under the GDPR, including the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, www.autoriteitpersoonsgegevens.nl).
Contact. Questions about this Data Processing Agreement may be addressed to Onavan B.V. (MilMap) via privacy@milmap.nl for privacy and GDPR matters, or via support@milmap.nl for general enquiries.